Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2019-14934: Comparing v0.17...v0.18 · enferex/pdfresurrect

An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn’t validate a certain size value, which leads to a malloc failure and out-of-bounds write.

CVE
#pdf

Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also .

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also .

base repository: enferex/pdfresurrect base: v0.17

head repository: enferex/pdfresurrect compare: v0.18

  • 11 commits
  • 4 files changed
  • 1 contributor

Commits on Aug 7, 2019

Commits on Aug 9, 2019

  1. Zero and extend a buffer.

    This should fix one of the ASAN discovered overflows in Issue #6. The test case is stackoverflow_some.pdf in that issue. Thanks to @rtfingc for finding and reporting this.

Commits on Aug 10, 2019

  1. Fix a memory leak.

    Thanks to @rtfing for pointing this out in Issue #6. This fixes bugs identified by memory_leak memleak2.pdf

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda