MGASA-2026-0229

Source
https://advisories.mageia.org/MGASA-2026-0229.html
Import Source
https://advisories.mageia.org/MGASA-2026-0229.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2026-0229
Upstream
Published
2026-06-24T05:41:50Z
Modified
2026-06-24T05:45:04.660751428Z
Summary
Updated podofo packages fix security vulnerabilities
Details

Podofo v0.9.8 shares some of the vulnerable code that was discovered in Podofo v0.10.0. This package fixes that. CVE-2023-31567 Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3. CVE-2023-31568 Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.

References
Credits

Affected packages

Mageia:9 / podofo

Package

Name
podofo
Purl
pkg:rpm/mageia/podofo?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.8-2.1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0229.json"