First published: Fri Oct 17 2014(Updated: )
Buffer overflow in the SetLogFile method in Foxit.FoxitPDFSDKProCtrl.5 in Foxit PDF SDK ActiveX 2.3 through 5.0.1820 before 5.0.2.924 allows remote attackers to execute arbitrary code via a long string, related to global variables.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Foxit Pdf Sdk Activex | =2.3 | |
Foxitsoftware Foxit Pdf Sdk Activex | =3.0 | |
Foxitsoftware Foxit Pdf Sdk Activex | =4.0 | |
Foxitsoftware Foxit Pdf Sdk Activex | =5.0.0 | |
Foxitsoftware Foxit Pdf Sdk Activex | =5.0.1.820 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8074 has a critical severity level due to its potential for remote code execution.
To fix CVE-2014-8074, update Foxit PDF SDK ActiveX to version 5.0.2.924 or later.
CVE-2014-8074 affects Foxit PDF SDK ActiveX versions 2.3 to 5.0.1.820.
CVE-2014-8074 is a buffer overflow vulnerability that may lead to arbitrary code execution.
Remote attackers can exploit CVE-2014-8074 by sending a specially crafted long string to the SetLogFile method.