A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential code execution. An attacker can send the victim a specific PDF file to trigger this vulnerability.
References
| Link | Resource |
|---|---|
| http://www.talosintelligence.com/reports/TALOS-2016-0224/ | Technical Description Third Party Advisory |
| http://www.securityfocus.com/bid/96155 |
Configurations
Information
Published : 2017-02-10 17:59
Updated : 2021-06-16 13:51
NVD link : CVE-2016-8711
Mitre link : CVE-2016-8711
JSON object : View
Products Affected
gonitro
- nitro_pdf_pro
CWE
CWE-20
Improper Input Validation
