CVE-2020-6116
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of a buffer when allocating space for its colors. When using this allocated buffer, the application can write outside its bounds and cause memory corruption which can lead to code execution. A specially crafted document must be loaded by a victim in order to trigger this vulnerability.
Se presenta una vulnerabilidad de ejecución de código arbitraria en la funcionalidad de renderizado de Nitro Pro de Nitro Software, Inc versión 13.13.2.242. Al dibujar el contenido de una página usando colores de un espacio de color indexado, la aplicación puede calcular inapropiadamente el tamaño de un búfer al asignar espacio para sus colores. Cuando usa este búfer asignado, la aplicación puede escribir fuera de sus límites y causar una corrupción de la memoria, lo que puede conllevar a una ejecución de código. La víctima debe cargar un documento especialmente diseñado para desencadenar esta vulnerabilidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-07 CVE Reserved
- 2020-09-17 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-131: Incorrect Calculation of Buffer Size
- CWE-190: Integer Overflow or Wraparound
- CWE-680: Integer Overflow to Buffer Overflow
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1070 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gonitro Search vendor "Gonitro" | Nitro Pro Search vendor "Gonitro" for product "Nitro Pro" | 13.13.2.242 Search vendor "Gonitro" for product "Nitro Pro" and version "13.13.2.242" | - |
Affected
| ||||||
Gonitro Search vendor "Gonitro" | Nitro Pro Search vendor "Gonitro" for product "Nitro Pro" | 13.16.2.300 Search vendor "Gonitro" for product "Nitro Pro" and version "13.16.2.300" | - |
Affected
|