Description


An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different places. When closed, the document will result in the reference being released twice. This can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger this vulnerability.

Related CPE's


a

gonitro

nitro_pro

2

Weaknesses



CWE-415


CWE-415

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-10-18T11:15:09.277Z

4 years ago

Last modified

2024-11-21T04:48:59.567Z

1 year ago