← Back to browse · API

CVE-2019-5066

Severity
CRITICAL
CVSS
9.8
EPSS
0.02375
Risk score
40.03
CISA KEV
No
PoC
No
Published
2019-09-18
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2019-14671, GHSA-JQG4-P627-84CF
Products
Talos:Aspose Aspose.PDF 19.2
Sources
euvd EUVD-2019-14671

Description

An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resulting in a use-after-free condition. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.

References