This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo Library. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within PdfEncoding::ParseToUnicode(). The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. References: https://www.zerodayinitiative.com/advisories/ZDI-18-1046/
Created podofo tracking bugs for this issue: Affects: epel-all [bug 1631431] Affects: fedora-all [bug 1631430]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.