QID 375993
Date Published: 2021-10-29
QID 375993: Nitro Pro PDF JavaScript Multiple Vulnerabilities
An exploitable double-free and use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF
Affected version:
Nitro Pro PDF Prior to 13.50.4.1013
QID Detection Logic:
It checks for vulnerable version of Nitro Pro by checking the file version of NitroPDF.exe.
This can lead to code execution under the context of the application.
Solution
Customers are advised to install the latest versions of Nitro PDF Pro 13 to remediate this vulnerability.
Vendor References
- gonitro -
www.gonitro.com/security/updates
CVEs related to QID 375993
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-21797,CVE-2021-21796 |
|