A heap-use-after free in the PdfTokenizer::ReadDictionary...
High severity
Unreviewed
Published
Oct 1, 2025
to the GitHub Advisory Database
•
Updated Oct 27, 2025
Description
Published by the National Vulnerability Database
Oct 1, 2025
Published to the GitHub Advisory Database
Oct 1, 2025
Last updated
Oct 27, 2025
A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PDF file.
References