First published: Mon Dec 16 2019(Updated: )
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gonitro Nitro Free Pdf Reader | =12.0.0.112 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-19817 is medium with a severity value of 5.5.
CVE-2019-19817 affects Nitro Free PDF Reader 12.0.0.112.
CVE-2019-19817 has a CWE ID of 125.
For more information on CVE-2019-19817, you can refer to the following references: - [GitHub](https://github.com/nafiez/nafiez.github.io/blob/master/_posts/2019-12-12-multiple-nitro-pdf-vulnerability.md) - [Blog Post](https://nafiez.github.io/security/vulnerability/remote/2019/12/12/multiple-nitro-pdf-vulnerability.html)
To fix the vulnerability in Nitro Free PDF Reader 12.0.0.112, it is recommended to update to a newer version or apply any available patches or security updates from the software vendor.