First published: Mon Dec 16 2019(Updated: )
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gonitro Nitro Free Pdf Reader | =12.0.0.112 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-19818 is medium with a severity value of 5.5.
The vulnerability in CVE-2019-19818 affects Nitro Free PDF Reader version 12.0.0.112.
The CWE ID associated with CVE-2019-19818 is CWE-125.
To fix the vulnerability in CVE-2019-19818, update Nitro Free PDF Reader to a version that is not affected.
You can find more information about CVE-2019-19818 in the referenced links: [link1](https://github.com/nafiez/nafiez.github.io/blob/master/_posts/2019-12-12-multiple-nitro-pdf-vulnerability.md) and [link2](https://nafiez.github.io/security/vulnerability/remote/2019/12/12/multiple-nitro-pdf-vulnerability.html).