20180227 ActivePDF Toolkit < 8.1.0 multiple RCEmailing list
http://seclists.org/fulldisclosure/2018/Feb/74 CVE-2018-7264
CRITICAL
ActivePDF Toolkit < 8.1.0.19023 - Multiple Memory Corruptions
Record summary
CVE-2018-7264 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBActivePDF Toolkit < 8.1.0.19023 - Multiple Memory CorruptionsExploitDB exploitby François GoichonNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-7264 44251exploit
https://www.exploit-db.com/exploits/44251