Loading HuntDB...

GHSA-gmc4-hh9v-xwm4

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer over-read in the exif processing module for a PNG file (during XPS conversion). Invalid input leads to a computation where pointer arithmetic results in a location outside valid memory locations belonging to the buffer. An attack can be used to obtain sensitive information, such as object heap addresses, etc.

Related CVEs

Key Information

GHSA ID
GHSA-gmc4-hh9v-xwm4
Published
May 13, 2022 1:44 AM
Last Modified
May 13, 2022 1:44 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 30, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.