CVE-2019-5066 is a critical use-after-free vulnerability affecting Aspose.PDF 19.2 for C++, specifically in its handling of LZW-compressed PDF streams. This flaw allows a specially crafted PDF document to cause a dangling heap pointer, leading to a use-after-free condition. With a CVSS score of 9.8, it poses a severe risk, enabling potential complete compromise of confidentiality, integrity, and availability without user interaction. While there is no evidence of active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media attention, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
19.2CPE matchmatch criteria | cpe:2.3:a:aspose:aspose.pdf_for_c\+\+:19.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.