VYPR
Unrated severityNVD Advisory· Published Oct 22, 2021· Updated Aug 4, 2024

CVE-2020-28969

CVE-2020-28969

Description

Aplioxio PDF ShapingUp 5.0.0.139 contains a buffer overflow which allows attackers to cause a denial of service (DoS) via a crafted PDF file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stack buffer overflow in Aplioxio PDF ShapingUp 5.0.0.139 allows attackers to cause a denial of service via a crafted PDF file.

Vulnerability

PDF ShapingUp v5.0.0.139 contains a stack buffer overflow vulnerability in the handling of PDF files [1]. When the application opens a specially crafted PDF, a buffer overflow occurs, potentially allowing arbitrary code execution. The vulnerability is pre-authentication and requires low user interaction.

Exploitation

An attacker can exploit this vulnerability by crafting a malicious PDF file and convincing a user to open it with PDF ShapingUp. No authentication is needed, and the attack can be performed remotely. Upon opening the file, the buffer overflow triggers, allowing the attacker to cause a denial of service or potentially execute arbitrary code.

Impact

Successful exploitation leads to a denial of service, and according to the advisory, may also allow remote code execution in the context of the application [1]. The impact is limited to the integrity and availability of the affected system, depending on the payload.

Mitigation

As of the latest available information, no official patch has been released for this vulnerability. Users should exercise caution when opening PDF files from untrusted sources and consider using alternative PDF editing software until a fix is available.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.