CVE-2019-5053: Use After Free
Published Oct 9, 2019
·Updated
An exploitable use-after-free vulnerability exists in the Length parsing function of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a use-after-free condition. An attacker can craft a malicious PDF to trigger this vulnerability.
Affected Software
1 affected component
Gonitro Nitropdf=12.2.1.522
Event History
Oct 9, 2019
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-5053?
CVE-2019-5053 is a use-after-free vulnerability in the Length parsing function of NitroPDF.
2
How does CVE-2019-5053 affect NitroPDF?
CVE-2019-5053 affects NitroPDF version 12.2.1.522.
3
What is the severity of CVE-2019-5053?
CVE-2019-5053 has a severity rating of 7.8 (high).
4
How can CVE-2019-5053 be exploited?
CVE-2019-5053 can be exploited by crafting a malicious PDF that triggers a use-after-free condition.
5
Is there a fix available for CVE-2019-5053?
At the moment, there is no specific fix available for CVE-2019-5053. It is recommended to update to the latest version of NitroPDF or apply any patches or security updates provided by the vendor.