CVE-2018-7264: Critical severity ActivePDF ActivePDF toolkit vulnerability
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7264?
CVE-2018-7264 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2018-7264?
To fix CVE-2018-7264, upgrade to a version of the ActivePDF Toolkit that is newer than 8.1.0.19023.
What types of attacks can be executed via CVE-2018-7264?
CVE-2018-7264 allows attackers to execute arbitrary code on applications processing untrusted images.
Which versions of ActivePDF Toolkit are affected by CVE-2018-7264?
ActivePDF Toolkit versions up to and including 8.1.0.19023 are affected by CVE-2018-7264.
Is there a known exploit for CVE-2018-7264?
Yes, there are known exploits available for CVE-2018-7264 that demonstrate how to leverage the vulnerability.