PT-2019-17407 · Rainbow · Rainbow Pdf Office Server Document Converter
Published
2019-03-07
·
Updated
2022-06-13
·
CVE-2019-5019
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rainbow PDF Office Server Document Converter version 7.0 Pro R1 (7,0,2018,1113)
Description
A heap-based overflow issue exists in the PowerPoint document conversion function. The
getSummaryInformation function incorrectly checks the correlation between size and the number of properties in PropertySet packets while parsing the Document Summary Property Set stream, leading to an out-of-bounds write, heap corruption, and potential code execution.Recommendations
For Rainbow PDF Office Server Document Converter version 7.0 Pro R1 (7,0,2018,1113), consider disabling the PowerPoint document conversion function until a patch is available. Restrict access to the
getSummaryInformation function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rainbow Pdf Office Server Document Converter