Intel

AIKIDO-2024-10461

bblanchon.PDFium.macOS is vulnerable to Undefined Behavior

Undefined Behavior Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 20, 2024

20

Low Risk

This Affects:

dotnetbblanchon.PDFium.macOS
97.0.4667 - 130.0.6721
Fixed in 133.0.6844
Are you affected? Scan for Free

TL;DR

Affected versions of this package have multiple weaknesses that can cause application crashes, resulting in undefined, unintended, and potentially dangerous behavior.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

bblanchon.PDFium.macOS is vulnerable to Undefined Behavior in versions 97.0.4667 - 130.0.6721.

How to fix this

Upgrade the bblanchon.PDFium.macOS library to the patch version.