Information Disclosure Vulnerability in PDF-XChange Editor JB2 File Parsing
CVE-2024-8823

5.5MEDIUM

Key Information:

Vendor
CVE Published:
22 November 2024

Summary

An information disclosure vulnerability has been identified in PDF-XChange Editor related to the parsing of JB2 files. The flaw arises due to inadequate validation of user-supplied data, which allows attackers to read beyond the end of an allocated object. Successful exploitation necessitates user interaction, requiring potential victims to visit a malicious webpage or open a specially crafted file. This vulnerability can be leveraged in conjunction with other weaknesses to execute arbitrary code within the context of the affected process, posing significant risks to users.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.