This update for podofo fixes the following issues:
CVE-2017-5852: The PoDoFo::PdfPage::GetInheritedKeyFromObject function
allowed remote attackers to cause a denial of service (infinite loop) via a
crafted file (bsc#1023067).
CVE-2017-5853: Integer overflow allowed remote attackers to have unspecified
impact via a crafted file (bsc#1023069).
CVE-2017-5854: Prevent NULL pointer dereference that allowed remote attackers
to cause a denial of service via a crafted file (bsc#1023070).
CVE-2017-5855: The PoDoFo::PdfParser::ReadXRefSubsection function allowed
remote attackers to cause a denial of service (NULL pointer dereference) via a
crafted file (bsc#1023071).
CVE-2017-5886: Prevent heap-based buffer overflow in the
PoDoFo::PdfTokenizer::GetNextToken function that allowed remote attackers to
have unspecified impact via a crafted file (bsc#1023380).
CVE-2017-6847: The PoDoFo::PdfVariant::DelayedLoad function allowed remote
attackers to cause a denial of service (NULL pointer dereference) via a crafted
file (bsc#1027778).
CVE-2017-6844: Buffer overflow in the PoDoFo::PdfParser::ReadXRefSubsection
function allowed remote attackers to have unspecified impact via a crafted file
(bsc#1027782).
CVE-2017-6840: The ColorChanger::GetColorFromStack function allowed remote
attackers to cause a denial of service (invalid read) via a crafted file
(bsc#1027787).
CVE-2017-7378: The PoDoFo::PdfPainter::ExpandTabs function allowed remote
attackers to cause a denial of service (heap-based buffer over-read and
application crash) via a crafted PDF document (bsc#1032017).
CVE-2017-7379: The PoDoFo::PdfSimpleEncoding::ConvertToEncoding function
allowed remote attackers to cause a denial of service (heap-based buffer
over-read and application crash) via a crafted PDF document (bsc#1032018).
CVE-2017-7380: Prevent NULL pointer dereference that allowed remote attackers
to cause a denial of service via a crafted PDF document (bsc#1032019).
CVE-2017-7994: The function TextExtractor::ExtractText allowed remote
attackers to cause a denial of service (NULL pointer dereference and
application crash) via a crafted PDF document (bsc#1035534).
CVE-2017-8054: The function PdfPagesTree::GetPageNodeFromArray allowed remote
attackers to cause a denial of service (infinite recursion and application
crash) via a crafted PDF document (bsc#1035596).
CVE-2017-8787: The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry
function allowed remote attackers to cause a denial of service (heap-based
buffer over-read) or possibly have unspecified other impact via a crafted PDF
file (bsc#1037739).
CVE-2018-5308: Properly validate memcpy arguments in the
PdfMemoryOutputStream::Write function to prevent remote attackers from causing
a denial-of-service or possibly have unspecified other impact via a crafted pdf
file (bsc#1075772).
CVE-2018-8001: Prevent heap-based buffer over-read vulnerability in
UnescapeName() that allowed remote attackers to cause a denial-of-service or
possibly unspecified other impact via a crafted pdf file (bsc#1084894).