Vulnerabilities > CVE-2019-5030 - Out-of-bounds Write vulnerability in Antennahouse Rainbow PDF Office Server Document Converter 7.0.2019.0220

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
antennahouse
CWE-787

Summary

A buffer overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro MR1 (7,0,2019,0220). While parsing a document text info container, the TxMasterStyleAtom::parse function is incorrectly checking the bounds corresponding to the number of style levels, causing a vtable pointer to be overwritten, which leads to code execution.

Vulnerable Configurations

Part Description Count
Application
Antennahouse
1

Common Weakness Enumeration (CWE)

Talos

idTALOS-2019-0792
last seen2019-11-07
published2019-05-14
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0792
titleAntenna House Rainbow PDF Office server document converter TxMasterStyleAtom parsing code execution vulnerability