PT-2019-17449 · Aspose · Aspose.Pdf

Published

2019-09-18

·

Updated

2022-06-27

·

CVE-2019-5067

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aspose.PDF version 19.2 for C++
Description The issue arises from the handling of invalid parent object pointers in Aspose.PDF for C++, which can lead to an uninitialized memory access vulnerability. A specially crafted PDF document can cause the application to read and write from uninitialized memory, resulting in memory corruption and potentially allowing arbitrary code execution.
Recommendations For Aspose.PDF version 19.2 for C++, consider avoiding the processing of untrusted or specially crafted PDF documents until a fix is available. As a temporary workaround, restrict the use of the application to trusted PDF files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-5067

Affected Products

Aspose.Pdf