activePDF Server Packet Processing Remote Heap Overflow Vulnerability
BID:28013
Info
activePDF Server Packet Processing Remote Heap Overflow Vulnerability
| Bugtraq ID: | 28013 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-5397 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Carsten Eiram from Secunia Research discovered this issue. |
| Vulnerable: |
ActivePDF activePDF Server 3.8.5 .14 ActivePDF activePDF Server 3.8.4 |
| Not Vulnerable: |
ActivePDF activePDF Server 3.8.6 .16 |
Discussion
activePDF Server Packet Processing Remote Heap Overflow Vulnerability
activePDF Server is prone to a remote heap-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the affected application. Failed attacks will likely cause denial-of-service conditions.
This issue affects activePDF Server 3.8.4 and 3.8.5.14; other versions may be affected as well.
activePDF Server is prone to a remote heap-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the affected application. Failed attacks will likely cause denial-of-service conditions.
This issue affects activePDF Server 3.8.4 and 3.8.5.14; other versions may be affected as well.
Exploit / POC
activePDF Server Packet Processing Remote Heap Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
activePDF Server Packet Processing Remote Heap Overflow Vulnerability
Solution:
Reports indicate that the vendor released fixes (activePDF Server 3.8.6.16 or later) to address this issue, but Symantec was not able to verify this information. Please see the references and contact the vendor for more information.
Solution:
Reports indicate that the vendor released fixes (activePDF Server 3.8.6.16 or later) to address this issue, but Symantec was not able to verify this information. Please see the references and contact the vendor for more information.
References
activePDF Server Packet Processing Remote Heap Overflow Vulnerability
References:
References:
- activePDF Server Packet Handling Buffer Overflow (Secunia)
- activePDF Server Product Page (activePDF)