Documalis · Documalis Free Pdf Editor · CVE-2020-7374
**Name of the Vulnerable Software and Affected Versions**
Documalis Free PDF Editor version 5.7.2.26
Documalis Free PDF Scanner version 5.7.2.122
**Description**
The issue arises from the improper validation of JPEG images within PDFs, which can be exploited to trigger a buffer overflow on the stack. This can lead to remote code execution with the privileges of the user running the software.
**Recommendations**
For Documalis Free PDF Editor version 5.7.2.26, update to a version that properly validates the contents of JPEG images to prevent buffer overflow attacks.
For Documalis Free PDF Scanner version 5.7.2.122, update to a version that correctly handles JPEG images within PDFs to mitigate the risk of remote code execution.