CVE-2019-5045: High severity nitrotech vulnerability
Published Oct 9, 2019
·Updated
A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.
Affected Software
1 affected component
Gonitro Nitropdf=12.12.1.522
Event History
Oct 9, 2019
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-5045?
CVE-2019-5045 is a vulnerability that can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522.
2
How can CVE-2019-5045 be exploited?
CVE-2019-5045 can be exploited by opening a specifically crafted jpeg2000 file embedded in a PDF file.
3
Which version of NitroPDF is affected by CVE-2019-5045?
NitroPDF version 12.12.1.522 is affected by CVE-2019-5045.
4
What is the severity of CVE-2019-5045?
CVE-2019-5045 has a severity rating of 7.8 (high).
5
Is there a fix available for CVE-2019-5045?
No specific fix information is available.