First published: Mon Oct 08 2012(Updated: )
Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PDF-XChange | =3.60.0128 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5324 is considered a critical vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2012-5324, upgrade to a patched version of PDF-XChange that addresses the buffer overflow issues.
CVE-2012-5324 affects Tracker Software PDF-XChange version 3.60.0128.
CVE-2012-5324 is a buffer overflow vulnerability found in the Pdf Printer Preferences ActiveX Control.
Yes, CVE-2012-5324 can be exploited remotely through specially crafted input parameters.