First published: Mon Sep 18 2017(Updated: )
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "Heap Corruption starting at wow64!Wow64NotifyDebugger+0x000000000000001d."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stdutility Stdu Viewer | =1.6.375 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14549 has a high severity rating due to the potential for arbitrary code execution or denial of service.
To fix CVE-2017-14549, update to a version of STDU Viewer that is not affected by this vulnerability.
CVE-2017-14549 can be exploited to execute arbitrary code or trigger a denial of service by using a crafted .djvu file.
Version 1.6.375 of STDU Viewer is vulnerable to CVE-2017-14549.
CVE-2017-14549 is caused by heap corruption related to the processing of .djvu files.