CVE-2023-42048: PDF-XChange Editor J2K File Parsing Uninitialized Variable Information Disclosure Vulnerability
PDF-XChange Editor J2K File Parsing Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of J2K files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20909.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42048?
CVE-2023-42048 is considered a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2023-42048?
To fix CVE-2023-42048, users should update their PDF-XChange Editor to the latest version provided by Tracker Software.
What type of information can be disclosed by exploiting CVE-2023-42048?
Exploiting CVE-2023-42048 can lead to the disclosure of sensitive information stored on affected installations of PDF-XChange Editor.
Is user interaction required for CVE-2023-42048 to be exploited?
Yes, user interaction is required to exploit CVE-2023-42048, making it dependent on the victim opening a maliciously crafted J2K file.
Which software is affected by CVE-2023-42048?
CVE-2023-42048 specifically affects PDF-XChange Editor developed by Tracker Software.