CVE-2024-12548: Tungsten Automation Power PDF JP2 File Parsing Use-After-Free Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files.The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12548?
CVE-2024-12548 is classified as a medium-severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2024-12548?
Fixing CVE-2024-12548 involves updating Tungsten Automation Power PDF to the latest version that addresses this vulnerability.
What is the impact of CVE-2024-12548?
CVE-2024-12548 can allow remote attackers to disclose sensitive information through user interaction.
Are all versions of Tungsten Automation Power PDF affected by CVE-2024-12548?
Yes, all affected installations of Tungsten Automation Power PDF are vulnerable to CVE-2024-12548 if they have not been updated.
What kind of user interaction is required to exploit CVE-2024-12548?
Exploitation of CVE-2024-12548 requires the user to visit a malicious page or open a malicious file.