Vulnerabilities > CVE-2019-5067 - Use of Uninitialized Resource vulnerability in Aspose Aspose.Pdf for C++ 19.2

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
aspose
CWE-908
critical

Summary

An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized memory, resulting in memory corruption and possibly arbitrary code execution. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.

Vulnerable Configurations

Part Description Count
Application
Aspose
1

Common Weakness Enumeration (CWE)

Talos

idTALOS-2019-0856
last seen2019-09-20
published2019-09-17
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0856
titleAspose.PDF for C++ parent generation remote code execution vulnerability