The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/44251/ | third party advisory vdb entry exploit |
http://seclists.org/fulldisclosure/2018/Feb/74 | mailing list third party advisory exploit |