Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 650436 (CVE-2018-5308, CVE-2018-5309, CVE-2018-6352, CVE-2018-8001) - app-text/podofo: multiple vulnerabilities
Summary: app-text/podofo: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2018-5308, CVE-2018-5309, CVE-2018-6352, CVE-2018-8001
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://sourceforge.net/p/podofo/code...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-03-13 20:26 UTC by tonemgub
Modified: 2019-03-12 06:38 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description tonemgub 2018-03-13 20:26:31 UTC
Name	CVE-2018-6352
Description	In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf file.

Name	CVE-2018-5308
Description	PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.

Name	CVE-2018-5309
Description	In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.

Name	CVE-2018-8001
Description	In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.

Reproducible: Always
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2018-03-13 20:51:36 UTC
Zac could you confirm if we are affected by those vulns? 

Thank you.
Comment 3 Zac Medico gentoo-dev 2018-07-27 05:41:54 UTC
I've added a podofo-0.9.6_p20180715 ebuild which includes fixes for CVE-2018-5308, CVE-2018-5309, and CVE-2018-8001, but CVE-2018-6352 remains unfixed:

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=289e000c530215f2c921ea3e21d195b37b390c9c

Earlier versions are affected by all 4 issues.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2019-03-12 06:38:40 UTC
GLSA Vote: No
Thank you all for you work. 
Closing as [noglsa].