Vulnerabilities > CVE-2019-5047 - Type Confusion vulnerability in Gonitro Nitropdf 12.2.1.522

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

An exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a Use After Free. An attacker can craft a malicious PDF to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Gonitro
1

Talos

idTALOS-2019-0816
last seen2019-10-12
published2019-10-09
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0816
titleNitroPDF CharProcs Remote Code Execution Vulnerability