CVE-2018-6462: High severity Tracker-software Pdf-xchange Viewer vulnerability
Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calculating on the basis of 1 bpc instead of 8 bpc, which might allow remote attackers to execute arbitrary code via a crafted PDF document.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PDF-XChange Viewerto a version that resolves this vulnerability.Fixed in 2.5.322.8 - Upgrade
Upgrade
Viewer AX SDKto a version that resolves this vulnerability.Fixed in 2.5.322.8
Event History
Frequently Asked Questions
What is CVE-2018-6462?
CVE-2018-6462 is a vulnerability that affects Tracker PDF-XChange Viewer and Viewer AX SDK before version 2.5.322.8.
What is the severity of CVE-2018-6462?
CVE-2018-6462 has a severity rating of 7.8, which is considered high.
How does CVE-2018-6462 work?
CVE-2018-6462 occurs when Tracker PDF-XChange Viewer and Viewer AX SDK mishandle the conversion from YCC to RGB color spaces by miscalculating on the basis of 1 bpc instead of 8 bpc, allowing remote attackers to potentially execute arbitrary code through a crafted PDF document.
Which software versions are affected by CVE-2018-6462?
CVE-2018-6462 affects Tracker PDF-XChange Viewer before version 2.5.322.8 and Tracker Viewer AX SDK before version 2.5.322.8.
How can I fix CVE-2018-6462?
To fix CVE-2018-6462, it is recommended to upgrade Tracker PDF-XChange Viewer and Tracker Viewer AX SDK to version 2.5.322.8 or later.