PT-2012-5923 · Tracker · Pdf-Xchange
Gjoko Krstic
·
Published
2012-10-08
·
Updated
2017-09-02
·
CVE-2012-5324
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tracker Software PDF-XChange version 3.60.0128
Description
The issue concerns buffer overflows in the Pdf Printer Preferences ActiveX Control. Remote attackers can execute arbitrary code by providing a long string in specific parameters. The parameters
sub path in the StoreInRegistry() function and sub key in the InitFromRegistry() function are vulnerable to this issue.Recommendations
For Tracker Software PDF-XChange version 3.60.0128, consider disabling the
StoreInRegistry() and InitFromRegistry() functions as a temporary workaround until a patch is available. Avoid using the sub path and sub key parameters in the affected API endpoints until the issue is resolved.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pdf-Xchange