Vulnerability Description
An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resulting in a use-after-free condition. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aspose | Aspose.Pdf For C\+\+ | 19.2 |
Related Weaknesses (CWE)
References
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0855ExploitThird Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0855ExploitThird Party Advisory
FAQ
What is CVE-2019-5066?
CVE-2019-5066 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resulting in a...
How severe is CVE-2019-5066?
CVE-2019-5066 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-5066?
Check the references section above for vendor advisories and patch information. Affected products include: Aspose Aspose.Pdf For C\+\+.