Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aleksander Nikolic

Researcher fromCisco Talos
#33868of 53,632
7.8Total CVSS
Vulnerabilities · 1
PT-2019-17433
7.8
2019-10-09
Nitro · Nitropdf · CVE-2019-5047
**Name of the Vulnerable Software and Affected Versions** NitroPDF (affected versions not specified) **Description** The issue is related to a Use After Free vulnerability in the CharProcs parsing functionality. It can be triggered by a specially crafted PDF, causing a type confusion that results in a Use After Free. An attacker can exploit this by crafting a malicious PDF. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.