7.5
CVSSv2

CVE-2019-9687

Published: 11/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

podofo project podofo 0.9.6

fedoraproject fedora 29

Vendor Advisories

Debian Bug report logs - #923469 libpodofo: CVE-2019-9199 Package: src:libpodofo; Maintainer for src:libpodofo is Mattia Rizzolo <mattia@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 28 Feb 2019 16:15:02 UTC Severity: important Tags: fixed-upstream, security, upstream Found in version ...
Debian Bug report logs - #924430 libpodofo: CVE-2019-9687 Package: src:libpodofo; Maintainer for src:libpodofo is Mattia Rizzolo <mattia@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 12 Mar 2019 21:39:04 UTC Severity: important Tags: security, upstream Found in version libpodofo/096 ...
PoDoFo 096 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfStringcpp ...