Release date:
Updated on:
Affected Systems:
Sodapdf Soda PDF Professional 1.2.155.1729
Description:
--------------------------------------------------------------------------------
Bugtraq id: 61727
CVE (CAN) ID: CVE-2013-3485
Soda PDF is a PDF software.
Soda PDF 5.1.183.10520 loading dwmapi. dll or api-ms-win-core-localregistry-l1-1-0.dll similar library approach is not secure, attackers can trick users to open a remote WebDAV or SMB shared PDF file, using this vulnerability can load arbitrary library.
<* Source: kaveh ghaemmaghami
Link: http://secunia.com/advisories/53207/
Http://xforce.iss.net/xforce/xfdb/86353
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Sodapdf
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://sodapdf.com/products/professional