Vulnerability Description
A heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro R1 (7,0,2018,1113). While parsing Document Summary Property Set stream, the getSummaryInformation function is incorrectly checking the correlation between size and the number of properties in PropertySet packets, causing an out-of-bounds write that leads to heap corruption and consequent code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rainbowpdf | Office Server Document Converter | 7.0 |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0780ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0780ExploitThird Party Advisory
FAQ
What is CVE-2019-5019?
CVE-2019-5019 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro R1 (7,0,2018,1113). While parsing Document Summary Pr...
How severe is CVE-2019-5019?
CVE-2019-5019 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-5019?
Check the references section above for vendor advisories and patch information. Affected products include: Rainbowpdf Office Server Document Converter.