vendor:
Nitro PDF Reader
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Heap Memory Corruption / DoS
119
CWE
Product Name: Nitro PDF Reader
Affected Version From: 1.4.2000
Affected Version To: 1.4.0.11
Patch Exists: YES
Related CWE: N/A
CPE: a:nitro_pdf:nitro_pdf_reader
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MS Windows XP Pro SP3
2011
Nitro PDF Reader 1.4.0 Remote Heap Memory Corruption / DoS PoC
The program suffers from a heap corruption vulnerability which can be exploited by malicious people to cause a denial of service and potentially compromise a vulnerable system. The vulnerability is caused when processing malicious PDF file which triggers a heap corruption state resulting in a crash.
Mitigation:
Update to the latest version of Nitro PDF Reader