PT-2019-17407 · Rainbow · Rainbow Pdf Office Server Document Converter

Published

2019-03-07

·

Updated

2022-06-13

·

CVE-2019-5019

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rainbow PDF Office Server Document Converter version 7.0 Pro R1 (7,0,2018,1113)
Description A heap-based overflow issue exists in the PowerPoint document conversion function. The getSummaryInformation function incorrectly checks the correlation between size and the number of properties in PropertySet packets while parsing the Document Summary Property Set stream, leading to an out-of-bounds write, heap corruption, and potential code execution.
Recommendations For Rainbow PDF Office Server Document Converter version 7.0 Pro R1 (7,0,2018,1113), consider disabling the PowerPoint document conversion function until a patch is available. Restrict access to the getSummaryInformation function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-5019

Affected Products

Rainbow Pdf Office Server Document Converter