PT-2019-15735 · Nitro · Nitro Pro
Published
2019-11-21
·
Updated
2021-07-21
·
CVE-2019-18958
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nitro Pro versions prior to 13.2
Description
The issue arises when Nitro Pro creates a debug.log file in the same directory as a .pdf file, specifically if the .pdf document was generated through an OCR operation on the JPEG output of a scanner. This can pose a security risk if the debug.log file is later edited and then executed.
Recommendations
For versions prior to 13.2, consider removing or restricting access to the debug.log file created by Nitro Pro to minimize potential risks. As a temporary workaround, avoid executing any debug.log files that may have been edited.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nitro Pro