CVE Vulnerabilities

CVE-2017-8053

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Apr 22, 2017 | Modified: Oct 03, 2019
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

PoDoFo 0.9.5 allows denial of service (infinite recursion and stack consumption) via a crafted PDF file in PoDoFo::PdfParser::ReadDocumentStructure (PdfParser.cpp).

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Podofo Podofo_project 0.9.5 (including) 0.9.5 (including)
Libpodofo Ubuntu artful *
Libpodofo Ubuntu bionic *
Libpodofo Ubuntu cosmic *
Libpodofo Ubuntu esm-apps/bionic *
Libpodofo Ubuntu esm-apps/xenial *
Libpodofo Ubuntu precise *
Libpodofo Ubuntu trusty *
Libpodofo Ubuntu upstream *
Libpodofo Ubuntu xenial *
Libpodofo Ubuntu yakkety *
Libpodofo Ubuntu zesty *

References