Impact
PoDoFo versions 1.0.0 through 1.1.1 contain a flaw in the handling of Indexed color‑space images that allows a heap out‑of‑bounds read in PdfColorSpaceFilterIndexed::FetchScanLine. The code fails to perform a runtime bounds check on pixel indices, allowing an attacker to craft a PDF with an image whose pixel index equals or exceeds the map size, causing the library to read beyond the bounds of the lookup table. This can expose adjacent heap data or trigger a crash, thereby enabling information disclosure or denial of service but not arbitrary code execution.
Affected Systems
The vulnerable product is the PoDoFo C++17 PDF manipulation library supplied by podofo:podofo. All releases from version 1.0.0 up to and including 1.1.1 are impacted. Version 1.1.1 contains the fix that removes the unchecked index usage and corrects the validation of Indexed color‑space metadata.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1% shows that exploitation is currently rare; the vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the flaw by supplying a specially crafted PDF to any application that processes PDFs with PoDoFo; if the application accepts user‑supplied files from the internet or a shared network location, the vector could be remote, otherwise local. The impact is limited to information disclosure or an application crash, but it remains a concern for systems that process untrusted PDF files.
OpenCVE Enrichment