HTTP: VeryPDF OpenPDF Unsafe ActiveX Method

This signature detects attempts to use unsafe ActiveX controls in VeryPDF PDFView. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

The VeryPDF PDFView ActiveX control is prone to a heap buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.

Affected Products

Verypdf pdfview

References

BugTraq: 32313

Short Name
HTTP:STC:ACTIVEX:VERYPDF
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
ActiveX Method OpenPDF Unsafe VeryPDF bid:32313
Release Date
09/14/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Verypdf

Found a potential security threat?