Related Vulnerabilities: CVE-2020-18972  

Exposure of sensitive information to an unauthorized actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.

Severity Medium

Remote Yes

Type Information disclosure

Description

Exposure of sensitive information to an unauthorized actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.

AVG-1427 podofo 0.9.7-1 Medium Vulnerable

https://sourceforge.net/p/podofo/tickets/49/
https://sourceforge.net/p/podofo/tickets/49/attachment/mem-leak