Description
A heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro R1 (7,0,2018,1113). While parsing Document Summary Property Set stream, the getSummaryInformation function is incorrectly checking the correlation between size and the number of properties in PropertySet packets, causing an out-of-bounds write that leads to heap corruption and consequent code execution.
Published: 2019-03-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-14626 A heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro R1 (7,0,2018,1113). While parsing Document Summary Property Set stream, the getSummaryInformation function is incorrectly checking the correlation between size and the number of properties in PropertySet packets, causing an out-of-bounds write that leads to heap corruption and consequent code execution.
History

No history.

Subscriptions

Rainbowpdf Office Server Document Converter
cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2024-08-04T19:40:49.300Z

Reserved: 2019-01-04T00:00:00.000Z

Link: CVE-2019-5019

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-03-07T20:29:00.390

Modified: 2024-11-21T04:44:11.970

Link: CVE-2019-5019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses