PT-2019-15735 · Nitro · Nitro Pro

Published

2019-11-21

·

Updated

2021-07-21

·

CVE-2019-18958

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nitro Pro versions prior to 13.2
Description The issue arises when Nitro Pro creates a debug.log file in the same directory as a .pdf file, specifically if the .pdf document was generated through an OCR operation on the JPEG output of a scanner. This can pose a security risk if the debug.log file is later edited and then executed.
Recommendations For versions prior to 13.2, consider removing or restricting access to the debug.log file created by Nitro Pro to minimize potential risks. As a temporary workaround, avoid executing any debug.log files that may have been edited.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18958

Affected Products

Nitro Pro