First published: Wed Feb 28 2018(Updated: )
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Activepdf Activepdf Toolkit | <8.1.0.19023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7264 is considered a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2018-7264, upgrade to a version of the ActivePDF Toolkit that is newer than 8.1.0.19023.
CVE-2018-7264 allows attackers to execute arbitrary code on applications processing untrusted images.
ActivePDF Toolkit versions up to and including 8.1.0.19023 are affected by CVE-2018-7264.
Yes, there are known exploits available for CVE-2018-7264 that demonstrate how to leverage the vulnerability.