PT-2008-6102 · Mw6 Technologies · Mw6Pdf417Lib.Pdf417
Deltahackingteam
·
Published
2008-11-04
·
Updated
2017-09-29
·
CVE-2008-4926
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MW6PDF417Lib.PDF417 version 3.0.0.1
Description
The issue concerns insecure methods in the MW6 Technologies PDF417 ActiveX control, allowing remote attackers to overwrite arbitrary files. This is achieved by providing a full pathname argument to the
SaveAsBMP and SaveAsWMF methods.Recommendations
For version 3.0.0.1, consider disabling the
SaveAsBMP and SaveAsWMF methods until a patch is available to prevent remote attackers from overwriting arbitrary files. Restrict access to the MW6PDF417.dll library to minimize the risk of exploitation. Avoid using the full pathname argument in the affected methods until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mw6Pdf417Lib.Pdf417