vendor:
Nitro PDF
by:
Francis Provencher
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Nitro PDF
Affected Version From: Nitro Pro 10.5.7.32 and lower
Affected Version To: Nitro Reader 5.5.3.1 and lower
Patch Exists: YES
Related CWE: N/A
CPE: a:gonitro:nitro_pdf
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2015
Nitro PDF Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Nitro PDF 10 (10.5.7.32). User interaction is required to exploit this vulnerability in that the target must open a malicious file. A specially crafted PDF with a specific FunctionType 0 and an invalid /Domain key can cause a stack-based buffer overflow, resulting in arbitrary code execution.
Mitigation:
GoNitro fixed this issue in 2016-01-21.