vendor:
DjVu ActiveX Control
by:
Shahriyar Jalayeri
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: DjVu ActiveX Control
Affected Version From: DjVu ActiveX Control 3.0 for Microsoft (r) Office
Affected Version To: Not mentioned
Patch Exists: NO
Related CWE: Not mentioned
CPE: a:djvu:djvu_activex_control:3.0
Platforms Tested: Windows
Not mentioned
DjVu ActiveX Control ImageURL Property Overflow
The vulnerability is in DjVu ActiveX Control 3.0 for Microsoft (r) Office ( DjVu_ActiveX_MSOffice.dll). The ImageURL property is vulnerable to a buffer overflow. It can be exploited using multiple techniques such as SEH overwrite and heap spray. Other properties like Mode, Page, and Zoom may also be vulnerable. The /SafeSEH option is also disabled.
Mitigation:
Apply the latest updates or patches from the vendor. Ensure that the DjVu ActiveX Control is used in a secure environment with restricted privileges. Disable the affected properties if they are not needed.