CVE Vulnerabilities

CVE-2017-8054

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Apr 22, 2017 | Modified: Oct 03, 2019
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The function PdfPagesTree::GetPageNodeFromArray in PdfPageTree.cpp:464 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted PDF document.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Podofo Podofo_project 0.9.5 (including) 0.9.5 (including)
Libpodofo Ubuntu artful *
Libpodofo Ubuntu esm-apps/xenial *
Libpodofo Ubuntu esm-infra-legacy/trusty *
Libpodofo Ubuntu precise *
Libpodofo Ubuntu trusty *
Libpodofo Ubuntu trusty/esm *
Libpodofo Ubuntu upstream *
Libpodofo Ubuntu xenial *
Libpodofo Ubuntu yakkety *
Libpodofo Ubuntu zesty *

References