NitroPDF¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-10-11·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5045£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-5050£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-5048£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-5047£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-5046£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-5053£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Nitro Software NitroPDF 12.12.1.522°æ±¾
·ì϶¸ÅÊö
Nitro Software NitroPDFÊÇÃÀ¹úNitro Software¹«Ë¾µÄÒ»¿îÓÃÓڲ鿴ºÍ±à×ëPDFÎļþµÄÈí¼þ¡£
˼¿ÆTalosÅû¶NitroPDFÖеĶà¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£Nitro PDFÔÊÐíÓû§ÔÚÆäÍÆËã»úÉϱ£Áô¡¢ÔĶÁºÍ±à×ëPDFÎļþ£¬¸Ã²úÆ··ÖΪÃâ·Ñ°æºÍÊշѰ档Õâ´Î·¢Ïֵķì϶¶¼´æÔÚÓÚÊշѵÄPro°æÖС£·ì϶Ô̺¬£º
jpeg2000 ssizDepthÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5045£©
¹¥»÷Õ߿ɽèÖú¶ñÒâµÄÎļþÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
Page KidsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5050£©
¹¥»÷Õ߿ɽèÖúÌØÔìµÄPDFÎļþÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
ICCBasedÉ«²Ê¿Õ¼äÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5048£©
¹¥»÷Õ߿ɽèÖúÌØÔìµÄPDFÎļþÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
CharProcsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5047£©
Nitro Software NitroPDFÖеÄCharProcs½âÎöÖ°ÄÜ´æÔÚ×ÊÔ´ÖÎÀíÃýÎó·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·¶Ôϵͳ×ÊÔ´£¨ÈçÄÚ´æ¡¢´ÅÅ̿ռ䡢ÎļþµÈ£©µÄÖÎÀí²»µ±¡£
jpeg2000 yTsizÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5046£©
¹¥»÷Õ߿ɽèÖú¶ñÒâµÄÎļþÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
Á÷³¤¶È½âÎöÖ°ÄÜÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-5053£©
Nitro Software NitroPDFÖеij¤¶È½âÎöº¯Êý´æÔÚ×ÊÔ´ÖÎÀíÃýÎó·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·¶Ôϵͳ×ÊÔ´£¨ÈçÄÚ´æ¡¢´ÅÅ̿ռ䡢ÎļþµÈ£©µÄÖÎÀí²»µ±¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://www.gonitro.com¡£
²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2019/10/vuln-spotlight-Nitro-PDF-RCE-bugs-sept-19.html


¾©¹«Íø°²±¸11010802024551ºÅ