PT-2007-7453 · Tracker Software Products · Pdf-Xchange

Fernando Muñoz

·

Publicado

2007-04-10

·

Atualizado

2018-10-30

·

CVE-2013-0729

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PDF-XChange versions prior to 2.5.208
Description A heap-based buffer overflow issue exists due to an error when processing a JPEG stream within a PDF file. This can be exploited to execute arbitrary code via a crafted Define Huffman Table header in a JPEG image file stream. Successful exploitation requires tricking a user into opening a malicious PDF document.
Recommendations For versions prior to 2.5.208, update to version 2.5.208 or later to resolve the issue. As a temporary workaround, consider avoiding the use of PDF-XChange to open PDF files from untrusted sources until the update is applied.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-0729

Produtos afetados

Pdf-Xchange