CVE-2019-5050: High severity nitrotech vulnerability
Published Oct 9, 2019
·Updated
A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.
Affected Software
1 affected component
Gonitro Nitropdf=12.12.1.522
Event History
Oct 9, 2019
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this heap corruption vulnerability in NitroPDF?
The vulnerability ID is CVE-2019-5050.
2
What is the severity rating of CVE-2019-5050?
The severity rating of CVE-2019-5050 is 7.8 (high).
3
Which software versions are affected by CVE-2019-5050?
NitroPDF version 12.12.1.522 is affected by CVE-2019-5050.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by opening a specifically crafted PDF file in NitroPDF version 12.12.1.522.
5
What is the fix for CVE-2019-5050?
Updating NitroPDF to a version after 12.12.1.522 can fix CVE-2019-5050.