PDF±à×ëÆ÷Able2ExtractÁ½¸öÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-11-06·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5088£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º8.8
CVE±àºÅ£ºCVE-2019-5089£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º8.8
Ó°Ïì°æ±¾
Investintech Able2Extract Professional 14.0.7 x64
·ì϶¸ÅÊö
Investintech Able2Extract ProfessionalÊǼÓÄôóInvestintech¹«Ë¾µÄÒ»¿îPDFÎĵµ×ª»»Æ÷ºÍ±à×ëÆ÷¡£¸Ã²úÆ·Ö§³ÖPDFÎĵµÉ¨Ãè¡¢PDF±à×ëºÍPDF²é¿´µÈ£¬ºÏÓÃÓÚWindows¡¢MacºÍLinuxµÈƽ̨¡£Æäרҵ°æÔÚ135¸ö¹ú¶È/µØÓòÕ¼Óг¬¹ý25ÍòÃûÓû§¡£
˼¿ÆTalos×êÑÐÈËÔ±·¢ÏÖInvestintechµÄAble2Extract Professional¹¤¾ß´æÔÚÁ½¸öÄÚ´æ°Ü»µ·ì϶£ºCVE-2019-5088ºÍCVE-2019-5089£¬¹¥»÷Õ߿ɽèÖúÌØÔìµÄBMPÎļþ»òÕßJPEGÎļþÀûÓ÷ì϶ÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐËÁÒâ´úÂë¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://www.investintech.com¡£
²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2019/11/vuln-spotlight-RCE-investintech-able2extract-nov-2019.html


¾©¹«Íø°²±¸11010802024551ºÅ