vendor:
PDF Explorer
by:
Gionathan 'John' Reale
7.5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: PDF Explorer
Affected Version From: 1.5.66.2
Affected Version To: 1.5.66.2
Patch Exists: Yes
Related CWE: N/A
CPE: a:rtt_software:pdf_explorer
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 32-bit
2018
PDF Explorer 1.5.66.2 – Denial of Service (PoC)
When a maliciously crafted file is opened in PDF Explorer 1.5.66.2, a denial of service (DoS) condition can be triggered. This is due to a buffer overflow error when the contents of the file are copied into the 'Label' field of the 'Custom fields settings' window. This causes the application to crash.
Mitigation:
Ensure that all software is up to date and patched with the latest security updates.