← Back to browse · API

CVE-2020-6116

Severity
HIGH
CVSS
8.8
EPSS
0.28424
Risk score
45.15
CISA KEV
No
PoC
No
Published
2020-09-17
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2020-27270, GHSA-QC5M-FQ47-QGPW
Products
Nitro:Nitro Pro Nitro Pro 13.13.2.242 ,Nitro Pro 13.16.2.300
Sources
euvd EUVD-2020-27270

Description

An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of a buffer when allocating space for its colors. When using this allocated buffer, the application can write outside its bounds and cause memory corruption which can lead to code execution. A specially crafted document must be loaded by a victim in order to trigger this vulnerability.

References