CVE Details
Basic Information
| Title | PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability |
|---|---|
| Type | cve |
| Published | 2025-06-25T21:40:27.368Z |
| Last Seen |
Product Information
| Vendor | PDF-XChange |
|---|---|
| Product | PDF-XChange Editor |
| Version | 10.5.2.395 |
CVSS Information
| Base Score | 0.0 () |
|---|---|
| Attack Vector | |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A heap-based buffer overflow vulnerability in PDF-XChange Editor allows remote code execution via malicious GIF files, requiring user interaction to exploit. |
|---|---|
| AI Severity | High |
| Vendor | PDF-XChange |
| Product | PDF-XChange Editor |
| Affected Version | 10.5.2.395 |
Affected Products
- PDF-XChange PDF-XChange Editor 10.5.2.395
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-122 |
| Bulletin Family |
References
Description
PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of GIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26763.