CVE-2023-39483: PDF-XChange Editor J2K File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
PDF-XChange Editor J2K File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of J2K files. Crafted data in a J2K file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18308.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39483?
The severity of CVE-2023-39483 is classified as medium due to the potential information disclosure.
How do I fix CVE-2023-39483?
To fix CVE-2023-39483, users should apply the latest updates and patches provided by PDF-XChange.
What are the potential impacts of CVE-2023-39483?
The potential impacts of CVE-2023-39483 include the disclosure of sensitive information if exploited by an attacker.
Is user interaction required to exploit CVE-2023-39483?
Yes, user interaction is required to exploit CVE-2023-39483 through the manipulation of J2K files.
Which software is affected by CVE-2023-39483?
CVE-2023-39483 affects the PDF-XChange Editor software by Tracker Software.