CVE-2020-10223: High severity nitro pro vulnerability
Published Mar 8, 2020
·Updated
npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::createpopupformarkup+0x12fbe via a crafted PDF document.
Affected Software
1 affected component
Gonitro Nitro Pro<13.13.2.242
Event History
Mar 8, 2020
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
Description
Frequently Asked Questions
1
What is CVE-2020-10223?
CVE-2020-10223 is a vulnerability in npdf.dll in Nitro Pro software before version 13.13.2.242 that allows for heap corruption via a crafted PDF document.
2
How severe is CVE-2020-10223?
CVE-2020-10223 has a severity score of 8.1, which is considered high.
3
How does CVE-2020-10223 affect Nitro Pro?
CVE-2020-10223 affects Nitro Pro versions up to and excluding 13.13.2.242.
4
What is the CWE classification for CVE-2020-10223?
CVE-2020-10223 is classified under CWE-787, which refers to use of incorrect or incompatible APIs.
5
Is there any fix available for CVE-2020-10223?
The recommended fix for CVE-2020-10223 is to update Nitro Pro to version 13.13.2.242 or later.