First published: Thu Feb 28 2008(Updated: )
Heap-based buffer overflow in the activePDF Server service (aka APServer.exe) in activePDF Server 3.8.4 and 3.8.5.14, and possibly other versions before 3.8.6.16, allows remote attackers to execute arbitrary code via a packet with a size field that is less than the actual size of the data.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
activePDF Server | <=3.8.5.14 | |
activePDF Server | <=3.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5397 is classified as a critical vulnerability due to the potential for remote code execution.
To mitigate CVE-2007-5397, upgrade to activePDF Server version 3.8.6.16 or later.
CVE-2007-5397 affects activePDF Server versions up to and including 3.8.5.14.
Yes, CVE-2007-5397 can be exploited remotely by sending specially crafted packets.
CVE-2007-5397 is a heap-based buffer overflow vulnerability.