CVE-2022-24960

A use after free vulnerability was discovered in PDFTron SDK version 9.2.0. A crafted PDF can overwrite RIP with data previously allocated on the heap. This issue affects: PDFTron PDFTron SDK 9.2.0 on OSX; 9.2.0 on Linux; 9.2.0 on Windows.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:pdftron:pdftron:9.2.0:*:*:*:*:*:*:*
OR cpe:2.3:a:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:51

Type Values Removed Values Added
References () https://github.com/suletm/security_research/blob/main/CVE/CVE-2022-24960.json - Third Party Advisory () https://github.com/suletm/security_research/blob/main/CVE/CVE-2022-24960.json - Third Party Advisory
References () https://www.pdftron.com/nightly/#stable/2022-02-08/9.2/ - Vendor Advisory () https://www.pdftron.com/nightly/#stable/2022-02-08/9.2/ - Vendor Advisory
CVSS v2 : 4.3
v3 : 7.8
v2 : 4.3
v3 : 6.5

Information

Published : 2022-03-10 17:46

Updated : 2024-11-21 06:51


NVD link : CVE-2022-24960

Mitre link : CVE-2022-24960

CVE.ORG link : CVE-2022-24960


JSON object : View

Products Affected

linux

  • linux_kernel

apple

  • macos

microsoft

  • windows

pdftron

  • pdftron
CWE
CWE-416

Use After Free