关键漏洞信息总结 Description: Vulnerability Type: Infinite Loop Vulnerable Function: in from the PoDoFo library Trigger: A fuzzing operation by uncovered the issue Affected Version: 0.9.4 Fixed Version: Not Available (N/A) Credit: This bug was discovered by Agostino Sarubbo of Gentoo. CVE: CVE-2017-5852 Reproducer: Available at the following GitHub link: PoDoFo infinite loop PoC Timeline: 2017-01-05: Bug Discovered 2017-02-01: Blog Post about the Issue 2017-02-02: CVE Assigned Note: Found with American Fuzzy Lop fuzzing tool