Researchers found serious flaws in Investintechs Able2Extract Professional tool that could be exploited to execute arbitrary code using specially crafted image files. The software is a cross-platform PDF tool for Windows, Mac and Linux that converts PDFs and allows users to create and edit them. The vulnerabilities affect Able2extract Professional version 14.0.7 x64 and are tracked as CVE-2019-5088 and CVE- 2019-5089. An attacker could trigger an out-of-bounds memory write by tricking users into opening specially crafted images.”]
Source: https://securityaffairs.co/wordpress/93424/hacking/able2extract-tool-flaws.html

