CVE Published: 12/08/2020 |
CVE Updated: 17/09/2024 |
CVE Year: 2020 Source: rapid7 |
Vendor: Documalis |
Product: Free PDF Editor Status : PUBLISHED
CVE-2020-7374 Description
Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit this vulnerability to trigger a buffer overflow on the stack and gain remote code execution as the user running the Documalis Free PDF Editor or Documalis Free PDF Scanner software.
Metrics
CVSS Version: 3.1 |
Base Score: 5.3 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L