Secunia Advisory SA33427PDFBuilderX ActiveX Control "SaveToFile()" Arbitrary File Overwrite
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Alfons Luja has discovered a vulnerability in PDFBuilderX, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to the PDFBuilderXTrial.PDFDoc ActiveX control (PDFBuilderXTrial.ocx) providing the insecure "SaveToFile()" method. This can be exploited to overwrite arbitrary files on the system in the context of the currently logged-on user. Successful exploitation allows execution of arbitrary code. The vulnerability is confirmed in PDFBuilderXTrial.ocx version 2.2.0.1. Other versions may also be affected. Solution Provided and/or discovered by Alternate/detailed remediation Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
151 views | ![]() |
| Limny Multiple Vulnerabilities | |
227 views | ![]() |
| Ubuntu update for thunderbird | |
172 views | ![]() |
| Debian update for php5 | |