Vulnerability Description
An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized memory, resulting in memory corruption and possibly arbitrary code execution. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aspose | Aspose.Pdf For C\+\+ | 19.2 |
Related Weaknesses (CWE)
References
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0856ExploitThird Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0856ExploitThird Party Advisory
FAQ
What is CVE-2019-5067?
CVE-2019-5067 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized mem...
How severe is CVE-2019-5067?
CVE-2019-5067 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-5067?
Check the references section above for vendor advisories and patch information. Affected products include: Aspose Aspose.Pdf For C\+\+.