Description: CVE-2017-5886 Acked-By: Markus Koschany Acked-By: Mattia Rizzolo Last-Update: 2017-05-03 Bug-Debian: https://bugs.debian.org/854604 Origin: https://sourceforge.net/p/podofo/code/1837 --- a/src/base/PdfTokenizer.cpp +++ b/src/base/PdfTokenizer.cpp @@ -239,7 +239,7 @@ *peType = ePdfTokenType_Token; while( (c = m_device.Device()->Look()) != EOF - && counter < static_cast(m_buffer.GetSize()) ) + && counter + 1 < static_cast(m_buffer.GetSize()) ) { // ignore leading whitespaces if( !counter && IsWhitespace( c ) )