PT-2019-17449 · Aspose · Aspose.Pdf
Published
2019-09-18
·
Updated
2022-06-27
·
CVE-2019-5067
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Aspose.PDF version 19.2 for C++
Description
The issue arises from the handling of invalid parent object pointers in Aspose.PDF for C++, which can lead to an uninitialized memory access vulnerability. A specially crafted PDF document can cause the application to read and write from uninitialized memory, resulting in memory corruption and potentially allowing arbitrary code execution.
Recommendations
For Aspose.PDF version 19.2 for C++, consider avoiding the processing of untrusted or specially crafted PDF documents until a fix is available. As a temporary workaround, restrict the use of the application to trusted PDF files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Uninitialized Resource
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aspose.Pdf