PT-2012-6299 · Sumatra · Sumatrapdf Reader
John Leitch
·
Published
2012-12-12
·
Updated
2020-03-11
·
CVE-2013-2830
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SumatraPDF Reader versions 2.x before 2.2.1
SumatraPDF Reader version 2.2.0 and earlier
Description
A use-after-free issue exists in the way SumatraPDF Reader handles objects in memory, allowing remote attackers to execute arbitrary code via a crafted PDF file. This could enable an attacker to gain the same user rights as the current user. If the current user has administrative rights, an attacker could take complete control of the affected system.
Recommendations
For SumatraPDF Reader versions 2.x before 2.2.1, update to version 2.2.1 or later to resolve the issue.
For SumatraPDF Reader version 2.2.0 and earlier, update to version 2.2.1 or later to resolve the issue.
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sumatrapdf Reader