PDF±à×ëÆ÷Able2ExtractÁ½¸öÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-11-06

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5088£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º8.8

CVE±àºÅ£ºCVE-2019-5089£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º8.8


Ó°Ïì°æ±¾


Investintech Able2Extract Professional 14.0.7 x64


·ì϶¸ÅÊö


Investintech Able2Extract ProfessionalÊǼÓÄôóInvestintech¹«Ë¾µÄÒ»¿îPDFÎĵµ×ª»»Æ÷ºÍ±à×ëÆ÷¡£¸Ã²úÆ·Ö§³ÖPDFÎĵµÉ¨Ãè¡¢PDF±à×ëºÍPDF²é¿´µÈ£¬ºÏÓÃÓÚWindows¡¢MacºÍLinuxµÈƽ̨¡£Æäרҵ°æÔÚ135¸ö¹ú¶È/µØÓòÕ¼Óг¬¹ý25ÍòÃûÓû§¡£


˼¿ÆTalos×êÑÐÈËÔ±·¢ÏÖInvestintechµÄAble2Extract Professional¹¤¾ß´æÔÚÁ½¸öÄÚ´æ°Ü»µ·ì϶£ºCVE-2019-5088ºÍCVE-2019-5089£¬¹¥»÷Õ߿ɽèÖúÌØÔìµÄBMPÎļþ»òÕßJPEGÎļþÀûÓ÷ì϶ÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐËÁÒâ´úÂë¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://www.investintech.com¡£


²Î¿¼Á´½Ó


https://blog.talosintelligence.com/2019/11/vuln-spotlight-RCE-investintech-able2extract-nov-2019.html