CVE-2019-5047: Use After Free
An exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a Use After Free. An attacker can craft a malicious PDF to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5047?
CVE-2019-5047 is a Use After Free vulnerability that exists in the CharProcs parsing functionality of NitroPDF.
How does CVE-2019-5047 work?
An attacker can craft a specially crafted PDF that triggers a type confusion, resulting in a Use After Free vulnerability.
What is the severity of CVE-2019-5047?
CVE-2019-5047 has a severity rating of 7.8 out of 10, which is considered high.
Which version of NitroPDF is affected by CVE-2019-5047?
NitroPDF version 12.2.1.522 is affected by CVE-2019-5047.
Is there a fix available for CVE-2019-5047?
At the time of writing, there is no specific fix available for CVE-2019-5047. It is recommended to update to the latest version of NitroPDF once a fix becomes available.