Skip to main content

Corel PDF Fusion Multiple Vulnerabilities

Last Update Date: 9 Jul 2013 10:37 Release Date: 9 Jul 2013 3250 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Two vulnerabilities have been identified in Corel PDF Fusion, which can be exploited by malicious people to compromise a user's system.

  1. The application loads a library (wintab32.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a ".pdf" or ".xps" file located on a remote WebDAV or SMB share.
  2. A boundary error exists when parsing names in ZIP directory entries of a XPS file and can be exploited to cause a stack-based buffer overflow by tricking a user into opening a specially crafted XPS file.

Successful exploitation of the vulnerabilities allows execution of arbitrary code.

 

Note: No official solution is currently available.


Impact

  • Remote Code Execution

System / Technologies affected

  • Corel PDF Fusion 1.x

Solutions

  • No official solution is currently available.

Vulnerability Identifier


Source


Related Link