CVE-2022-24960

A use after free vulnerability was discovered in PDFTron SDK version 9.2.0. A crafted PDF can overwrite RIP with data previously allocated on the heap. This issue affects: PDFTron PDFTron SDK 9.2.0 on OSX; 9.2.0 on Linux; 9.2.0 on Windows.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:pdftron:pdftron:9.2.0:*:*:*:*:*:*:*
OR cpe:2.3:a:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:51

Type Values Removed Values Added
CVSS v2 : 4.3
v3 : 7.8
v2 : 4.3
v3 : 6.5
References () https://github.com/suletm/security_research/blob/main/CVE/CVE-2022-24960.json - Third Party Advisory () https://github.com/suletm/security_research/blob/main/CVE/CVE-2022-24960.json - Third Party Advisory
References () https://www.pdftron.com/nightly/#stable/2022-02-08/9.2/ - Vendor Advisory () https://www.pdftron.com/nightly/#stable/2022-02-08/9.2/ - Vendor Advisory

17 Mar 2022, 19:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 7.8
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:pdftron:pdftron:9.2.0:*:*:*:*:*:*:*
CWE CWE-416
References (MISC) https://github.com/suletm/security_research/blob/main/CVE/CVE-2022-24960.json - (MISC) https://github.com/suletm/security_research/blob/main/CVE/CVE-2022-24960.json - Third Party Advisory
References (MISC) https://www.pdftron.com/nightly/#stable/2022-02-08/9.2/ - (MISC) https://www.pdftron.com/nightly/#stable/2022-02-08/9.2/ - Vendor Advisory

10 Mar 2022, 17:53

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-10 17:46

Updated : 2024-11-21 06:51


NVD link : CVE-2022-24960

Mitre link : CVE-2022-24960

CVE.ORG link : CVE-2022-24960


JSON object : View

Products Affected

apple

  • macos

microsoft

  • windows

linux

  • linux_kernel

pdftron

  • pdftron
CWE
CWE-416

Use After Free