Foxit ActiveX Pro SDK 'SetLogFile()' ActiveX Control Buffer Overflow Vulnerability
BID:70608
Info
Foxit ActiveX Pro SDK 'SetLogFile()' ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 70608 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-8074 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2014 12:00AM |
| Updated: | Oct 16 2014 12:00AM |
| Credit: | Andrea Micalizzi (rgod) |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Foxit ActiveX Pro SDK 'SetLogFile()' ActiveX Control Buffer Overflow Vulnerability
Foxit ActiveX Pro SDK is prone to a buffer-overflow vulnerability because the applications fail to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Foxit ActiveX Pro SDK is prone to a buffer-overflow vulnerability because the applications fail to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Foxit ActiveX Pro SDK 'SetLogFile()' ActiveX Control Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Foxit ActiveX Pro SDK 'SetLogFile()' ActiveX Control Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Foxit ActiveX Pro SDK 'SetLogFile()' ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Foxit Homepage (Foxit Software)
- Foxit ActiveX Pro SDK SetLogFile Buffer Overflow Remote Code Execution Vulnerabi (TippingPoint Zero Day Initiative)