PDF Extract TIFF 'pdf2tif.dll' Buffer Overflow Vulnerability
BID:47322
Info
PDF Extract TIFF 'pdf2tif.dll' Buffer Overflow Vulnerability
| Bugtraq ID: | 47322 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2011 12:00AM |
| Updated: | Apr 14 2011 05:24AM |
| Credit: | JODE |
| Vulnerable: |
VeryPDF PDF Extract TIFF 0 Softek Software Barcode Reader Toolkit 7.4.1 3 |
| Not Vulnerable: |
Softek Software Barcode Reader Toolkit 7.4.1 5 |
Discussion
PDF Extract TIFF 'pdf2tif.dll' Buffer Overflow Vulnerability
PDF Extract TIFF is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
PDF Extract TIFF is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Exploit / POC
PDF Extract TIFF 'pdf2tif.dll' Buffer Overflow Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
PDF Extract TIFF 'pdf2tif.dll' Buffer Overflow Vulnerability
Solution:
Reportedly, the vendor has fixed the issue; however, Symantec has not confirmed it. Please contact the vendor for more information.
Solution:
Reportedly, the vendor has fixed the issue; however, Symantec has not confirmed it. Please contact the vendor for more information.
References
PDF Extract TIFF 'pdf2tif.dll' Buffer Overflow Vulnerability
References:
References:
- nSense Vulnerability Research Security Advisory NSENSE-2010-006 (nSense)
- VeryPDF Homepage (VeryPDF)