NitroPDF¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5045£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5050£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5048£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5047£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5046£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5053£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Nitro Software NitroPDF 12.12.1.522°æ±¾


Îó²î¸ÅÊö


Nitro Software NitroPDFÊÇÃÀ¹úNitro Software¹«Ë¾µÄÒ»¿îÓÃÓÚÉó²éºÍ±à¼­PDFÎļþµÄÈí¼þ¡£¡£¡£¡£¡£


˼¿ÆTalosÅû¶NitroPDFÖеĶà¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£Nitro PDFÔÊÐíÓû§ÔÚÆäÅÌËã»úÉÏÉúÑÄ¡¢ÔĶÁºÍ±à¼­PDFÎļþ£¬ £¬£¬¸Ã²úÆ··ÖΪÃâ·Ñ°æºÍÊշѰæ¡£¡£¡£¡£¡£´Ë´Î·¢Ã÷µÄÎó²î¶¼±£´æÓÚÊշѵÄPro°æÖС£¡£¡£¡£¡£Îó²î°üÀ¨£º


jpeg2000 ssizDepthÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5045£©

¹¥»÷Õ߿ɽèÖú¶ñÒâµÄÎļþʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


Page KidsÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5050£©

¹¥»÷Õ߿ɽèÖúÌØÖÆµÄPDFÎļþʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


ICCBasedÉ«²Ê¿Õ¼äÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5048£©

¹¥»÷Õ߿ɽèÖúÌØÖÆµÄPDFÎļþʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


CharProcsÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5047£©

Nitro Software NitroPDFÖеÄCharProcsÆÊÎö¹¦Ð§±£´æ×ÊÔ´ÖÎÀí¹ýʧÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·¶Ôϵͳ×ÊÔ´£¨ÈçÄÚ´æ¡¢´ÅÅ̿ռ䡢ÎļþµÈ£©µÄÖÎÀí²»µ±¡£¡£¡£¡£¡£


jpeg2000 yTsizÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5046£©

¹¥»÷Õ߿ɽèÖú¶ñÒâµÄÎļþʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


Á÷³¤¶ÈÆÊÎö¹¦Ð§ÄÚ´æËð»µÎó²î£¨CVE-2019-5053£©

Nitro Software NitroPDFÖеij¤¶ÈÆÊÎöº¯Êý±£´æ×ÊÔ´ÖÎÀí¹ýʧÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·¶Ôϵͳ×ÊÔ´£¨ÈçÄÚ´æ¡¢´ÅÅ̿ռ䡢ÎļþµÈ£©µÄÖÎÀí²»µ±¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥½â¾ö´ËÇå¾²ÎÊÌ⣬ £¬£¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö²½·¥£ºhttps://www.gonitro.com¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.talosintelligence.com/2019/10/vuln-spotlight-Nitro-PDF-RCE-bugs-sept-19.html