PDF±à¼­Æ÷Able2ExtractÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-11-06

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5088£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º8.8

CVE±àºÅ£ºCVE-2019-5089£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º8.8


Ó°Ïì°æ±¾


Investintech Able2Extract Professional 14.0.7 x64


Îó²î¸ÅÊö


Investintech Able2Extract ProfessionalÊǼÓÄôóInvestintech¹«Ë¾µÄÒ»¿îPDFÎĵµ×ª»»Æ÷ºÍ±à¼­Æ÷¡£¡£¡£¡£¸Ã²úÆ·Ö§³ÖPDFÎĵµÉ¨Ãè¡¢PDF±à¼­ºÍPDFÉó²éµÈ£¬£¬£¬ÊÊÓÃÓÚWindows¡¢MacºÍLinuxµÈƽ̨¡£¡£¡£¡£Æäרҵ°æÔÚ135¸ö¹ú¼Ò/µØÇøÓµÓÐÁè¼Ý25ÍòÃûÓû§¡£¡£¡£¡£


˼¿ÆTalosÑо¿Ö°Ô±·¢Ã÷InvestintechµÄAble2Extract Professional¹¤¾ß±£´æÁ½¸öÄÚ´æËð»µÎó²î£ºCVE-2019-5088ºÍCVE-2019-5089£¬£¬£¬¹¥»÷Õ߿ɽèÖúÌØÖÆµÄBMPÎļþ»òÕßJPEGÎļþʹÓÃÎó²îÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://www.investintech.com¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.talosintelligence.com/2019/11/vuln-spotlight-RCE-investintech-able2extract-nov-2019.html