Vulnerabilities > CVE-2020-6093 - Access of Uninitialized Pointer vulnerability in Gonitro Nitro PRO 13.9.1.155

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE

Summary

An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory access resulting in information disclosure. In order to trigger this vulnerability, victim must open a malicious file.

Vulnerable Configurations

Part Description Count
Application
Gonitro
1

Common Weakness Enumeration (CWE)

Talos

idTALOS-2020-1014
last seen2020-05-21
published2020-05-18
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1014
titleNitro Pro PDF Javascript XML error handling Information Disclosure Vulnerability