First published: Wed Oct 09 2019(Updated: )
A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gonitro Nitropdf | =12.12.1.522 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-5050.
The severity rating of CVE-2019-5050 is 7.8 (high).
NitroPDF version 12.12.1.522 is affected by CVE-2019-5050.
This vulnerability can be exploited by opening a specifically crafted PDF file in NitroPDF version 12.12.1.522.
Updating NitroPDF to a version after 12.12.1.522 can fix CVE-2019-5050.