Vulnerability Description
An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flowpaper | Pdf2Json | 0.69 |
Related Weaknesses (CWE)
References
- https://github.com/flexpaper/pdf2json/issues/20ExploitThird Party Advisory
- https://github.com/fouzhe/security/tree/master/pdf2json#alloc_dealloc_mismatch-iExploitThird Party Advisory
- https://github.com/flexpaper/pdf2json/issues/20ExploitThird Party Advisory
- https://github.com/fouzhe/security/tree/master/pdf2json#alloc_dealloc_mismatch-iExploitThird Party Advisory
FAQ
What is CVE-2018-14947?
CVE-2018-14947 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).
How severe is CVE-2018-14947?
CVE-2018-14947 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14947?
Check the references section above for vendor advisories and patch information. Affected products include: Flowpaper Pdf2Json.