A heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro R1 (7,0,2018,1113). While parsing Document Summary Property Set stream, the getSummaryInformation function is incorrectly checking the correlation between size and the number of properties in PropertySet packets, causing an out-of-bounds write that leads to heap corruption and consequent code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published: 2019-03-07T20:00:00

Updated: 2024-08-04T19:40:49.300Z

Reserved: 2019-01-04T00:00:00

Link: CVE-2019-5019

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-03-07T20:29:00.390

Modified: 2022-06-13T18:58:24.773

Link: CVE-2019-5019

cve-icon Redhat

No data.