Beveiligingsadvies

CVE-2019-5047

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-10-09 20:40:10
Laatst bijgewerkt 2024-08-04 19:47:55
Toegewezen door talos
CVSS-score 7.5
Status PUBLISHED

Beschrijving

An exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a Use After Free. An attacker can craft a malicious PDF to trigger this vulnerability.