
Cloud Vulnerability DB
A community-led vulnerabilities database
PDFio, a simple C library for reading and writing PDF files, contains a denial of service (DOS) vulnerability in its TTF parser identified as CVE-2024-42358. The vulnerability was discovered and disclosed on August 6, 2024, affecting all versions up to 1.3.0. When processing maliciously crafted TTF files, the parser can be forced to utilize 100% of memory and enter an infinite loop, potentially leading to a heap-buffer-overflow condition (GitHub Advisory, NVD).
The vulnerability occurs in the TTF parser's read_cmap function, specifically triggered by manipulating the nGroups value. The issue manifests when a maliciously crafted value is extracted from the file, causing the program to enter an infinite loop and consume excessive memory. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (MEDIUM) by NIST with a vector of CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, while GitHub assessed it at 6.2 (MEDIUM) with a vector of CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).
The vulnerability can significantly impact systems that use PDFio, particularly automated systems and web servers that process PDF submissions containing TTF fonts. When exploited, the vulnerability can cause denial of service conditions by consuming 100% of system memory and entering an infinite loop. Additionally, the issue can lead to heap-buffer-overflow vulnerabilities, potentially affecting system stability and security (GitHub Advisory).
The vulnerability can be triggered by uploading a maliciously crafted TTF file to systems using the affected PDFio versions. The exploit requires no special privileges but does need the ability to submit files for processing. The vulnerability has been demonstrated to be reliably exploitable through specially crafted TTF files (GitHub Advisory).
The vulnerability has been addressed in PDFio version 1.3.1. All users are advised to upgrade to this version as there are no known workarounds for this vulnerability. The fix includes implementation of proper range checking in the TTF loader (NVD, GitHub Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."