NitroPDF¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5045 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5050 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5048 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5047 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5046 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5053 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Nitro Software NitroPDF 12.12.1.522°æ±¾


·ì϶¸ÅÊö


Nitro Software NitroPDFÊÇÃÀ¹úNitro Software¹«Ë¾µÄÒ»¿îÓÃÓڲ鿴ºÍ±à×ëPDFÎļþµÄÈí¼þ¡£


˼¿ÆTalosÅû¶NitroPDFÖеĶà¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£Nitro PDFÔÊÐíÓû§ÔÚÆäÍÆËã»úÉϱ£Áô¡¢ÔĶÁºÍ±à×ëPDFÎļþ £¬¸Ã²úÆ··ÖΪÃâ·Ñ°æºÍÊշѰæ¡£Õâ´Î·¢Ïֵķì϶¶¼´æÔÚÓÚÊշѵÄPro°æÖС£·ì϶Ô̺¬£º


jpeg2000 ssizDepthÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5045£©

¹¥»÷Õ߿ɽèÖú¶ñÒâµÄÎļþÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£


Page KidsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5050£©

¹¥»÷Õ߿ɽèÖúÌØÔìµÄPDFÎļþÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£


ICCBasedÉ«²Ê¿Õ¼äÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5048£©

¹¥»÷Õ߿ɽèÖúÌØÔìµÄPDFÎļþÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£


CharProcsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5047£©

Nitro Software NitroPDFÖеÄCharProcs½âÎöÖ°ÄÜ´æÔÚ×ÊÔ´ÖÎÀíÃýÎó·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·¶Ôϵͳ×ÊÔ´£¨ÈçÄÚ´æ¡¢´ÅÅ̿ռ䡢ÎļþµÈ£©µÄÖÎÀí²»µ±¡£


jpeg2000 yTsizÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5046£©

¹¥»÷Õ߿ɽèÖú¶ñÒâµÄÎļþÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£


Á÷³¤¶È½âÎöÖ°ÄÜÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-5053£©

Nitro Software NitroPDFÖеij¤¶È½âÎöº¯Êý´æÔÚ×ÊÔ´ÖÎÀíÃýÎó·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·¶Ôϵͳ×ÊÔ´£¨ÈçÄÚ´æ¡¢´ÅÅ̿ռ䡢ÎļþµÈ£©µÄÖÎÀí²»µ±¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌâ £¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://www.gonitro.com¡£


²Î¿¼Á´½Ó


https://blog.talosintelligence.com/2019/10/vuln-spotlight-Nitro-PDF-RCE-bugs-sept-19.html