HIGH
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10
Published Feb 10, 2017
7.8
HIGHCVSS 3.1
EPSS 1.29%
Description
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger this vulnerability.
Affected products
-
- Version 10.5.9.9 (Nitro PDF Library - 10, 5, 9, 9) - x64 versionStatusaffectedConstraints-
- Version
- ≤ 10.5.9.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.securityfocus.com/bid/96155 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0218/ x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2016-9548 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/96155 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.talosintelligence.com/reports/TALOS-2016-0218/ | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2016-9548 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Feb 10, 2017
Updated Aug 6, 2024
Reserved Oct 17, 2016
Link CVE-2016-8709
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2016-9548 Assigner talos
Published Feb 10, 2017
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2016-9548