PT-2012-5923 · Tracker · Pdf-Xchange

Gjoko Krstic

·

Published

2012-10-08

·

Updated

2017-09-02

·

CVE-2012-5324

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tracker Software PDF-XChange version 3.60.0128
Description The issue concerns buffer overflows in the Pdf Printer Preferences ActiveX Control. Remote attackers can execute arbitrary code by providing a long string in specific parameters. The parameters sub path in the StoreInRegistry() function and sub key in the InitFromRegistry() function are vulnerable to this issue.
Recommendations For Tracker Software PDF-XChange version 3.60.0128, consider disabling the StoreInRegistry() and InitFromRegistry() functions as a temporary workaround until a patch is available. Avoid using the sub path and sub key parameters in the affected API endpoints until the issue is resolved.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5324

Affected Products

Pdf-Xchange