CVE-2020-6093: Medium severity nitro pro vulnerability
Published May 18, 2020
·Updated
An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory access resulting in information disclosure. In order to trigger this vulnerability, victim must open a malicious file.
Affected Software
1 affected component
Gonitro Nitro Pro=13.9.1.155
Event History
May 18, 2020
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this information disclosure vulnerability?
The vulnerability ID for this information disclosure vulnerability is CVE-2020-6093.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is Gonitro Nitro Pro version 13.9.1.155.
3
How does this vulnerability occur?
This vulnerability occurs due to uninitialized memory access during XML error handling in Nitro Pro.
4
What is the severity of CVE-2020-6093?
The severity of CVE-2020-6093 is medium with a severity value of 5.5.
5
How can I trigger this vulnerability?
To trigger this vulnerability, you need to open a specially crafted PDF document.