PDF±à¼­Æ÷Able2ExtractÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-11-06

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5088£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º8.8

CVE±àºÅ£ºCVE-2019-5089£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º8.8


Ó°Ïì°æ±¾


Investintech Able2Extract Professional 14.0.7 x64


Îó²î¸ÅÊö


Investintech Able2Extract ProfessionalÊǼÓÄôóInvestintech¹«Ë¾µÄÒ»¿îPDFÎĵµ×ª»»Æ÷ºÍ±à¼­Æ÷¡£¡£¡£¡£¡£¸Ã²úÆ·Ö§³ÖPDFÎĵµÉ¨Ãè¡¢PDF±à¼­ºÍPDFÉó²éµÈ£¬£¬£¬£¬ÊÊÓÃÓÚWindows¡¢MacºÍLinuxµÈƽ̨¡£¡£¡£¡£¡£Æäרҵ°æÔÚ135¸ö¹ú¼Ò/µØÇøÓµÓÐÁè¼Ý25ÍòÃûÓû§¡£¡£¡£¡£¡£


˼¿ÆTalosÑо¿Ö°Ô±·¢Ã÷InvestintechµÄAble2Extract Professional¹¤¾ß±£´æÁ½¸öÄÚ´æËð»µÎó²î£ºCVE-2019-5088ºÍCVE-2019-5089£¬£¬£¬£¬¹¥»÷Õ߿ɽèÖúÌØÖÆµÄBMPÎļþ»òÕßJPEGÎļþʹÓÃÎó²îÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://www.investintech.com¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.talosintelligence.com/2019/11/vuln-spotlight-RCE-investintech-able2extract-nov-2019.html