First published: Wed Oct 09 2019(Updated: )
A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gonitro Nitropdf | =12.2.1.522 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5048 is a vulnerability that allows a specially crafted PDF file to cause heap corruption and potential arbitrary code execution in NitroPDF 12.12.1.522.
CVE-2019-5048 has a severity rating of 7.8, which is considered high.
NitroPDF version 12.12.1.522 is affected by CVE-2019-5048.
CVE-2019-5048 can be exploited by tricking a victim into opening a malicious PDF file that triggers the heap corruption vulnerability in NitroPDF.
It is recommended to update NitroPDF to a version that is not affected by CVE-2019-5048 to mitigate the vulnerability.