CVE-2020-6112
An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data, the application can miscalculate a pointer for the stripes in the tile which allow for the decoder to write out of-bounds and cause memory corruption. This can result in code execution. A specially crafted image can be embedded inside a PDF and loaded by a victim in order to trigger this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.05%
- CWE
- CWE-823
- Published
- 2020-09-17
- Last modified
- 2026-03-14
Affected products
- n/a Nitro Pro
Weakness type
Related vulnerabilities
- CVE-2023-33106 — Use of Out-of-range Pointer Offset in Graphics
- CVE-2023-43553 — Use of Out-of-range Pointer Offset in WLAN HOST
- CVE-2023-24855 — Use of Out-of-range Pointer Offset in Modem
- CVE-2023-22388 — Use of Out-of-range Pointer Offset in Multi-mode Call Processor
- CVE-2026-21732 — GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilation
- CVE-2017-11076 — Use of Out-of-range Pointer Offset in Video
- CVE-2025-27059 — Use of Out-of-range Pointer Offset in TZ Firmware
- CVE-2023-46724 — SQUID-2023:4 Denial of Service in SSL Certificate validation