Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calculating on the basis of 1 bpc instead of 8 bpc, which might allow remote attackers to execute arbitrary code via a crafted PDF document.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://herolab.usd.de/wp-content/uploads/sites/4/2018/07/usd20180019.txt - | |
References | () https://www.tracker-software.com/company/news_press_events/view/179 - Patch, Vendor Advisory |
Information
Published : 2018-01-31 18:29
Updated : 2024-11-21 04:10
NVD link : CVE-2018-6462
Mitre link : CVE-2018-6462
CVE.ORG link : CVE-2018-6462
JSON object : View
Products Affected
tracker-software
- pdf-xchange_viewer
- viewer_ax_sdk
CWE
CWE-787
Out-of-bounds Write