VDB
CVE-2021-30470
CVE-2021-30470
PUBLISHED
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.
EPSS 0.11% · 28.6th percentile
Risk Scores
EPSS Score
0.11%
28.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:20.04:LTS | libpodofo | 0, 0.9.6+dfsg-5build1, * |
| Ubuntu:Pro:22.04:LTS | libpodofo | 0, 0.9.7+dfsg-2, * |
Exploit Intelligence
Timeline
- May 26, 2021 CVE Published
- May 27, 2021 EPSS Score
- Jul 29, 2021 EPSS Score
- Sep 28, 2021 EPSS Score
- Nov 29, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Mar 31, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 31, 2022 EPSS Score
- Aug 2, 2022 EPSS Score
- Oct 2, 2022 EPSS Score
- Dec 2, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2021-30470 third-party-advisory
- https://sourceforge.net/p/podofo/tickets/130/ third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2021-30470 third-party-advisory
- https://ubuntu.com/security/notices/USN-7217-1 vendor-advisory