CVE Vulnerabilities

CVE-2021-21798

Published: Sep 15, 2021 | Modified: Oct 25, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to go out of scope, resulting in the application dereferencing a stale pointer. This can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger the vulnerability.

Affected Software

Name Vendor Start Version End Version
Nitro_pro Gonitro 13.31.0.605 (including) 13.31.0.605 (including)
Nitro_pro Gonitro 13.33.2.645 (including) 13.33.2.645 (including)

References