PDF-XChange Editor
cpe:2.3:a:pdf-xchange:pdf-xchange_editor:*:*:*:*:*:*:*
- 10.7.2.400
A NULL pointer dereference vulnerability has been identified in PDF-XChange Editor version 10.7.3.401. This vulnerability arises in the util.readFileIntoStream component, where improper handling of a crafted input leads to an access violation. When the readFileIntoStream method is called with maliciously crafted data, the application fails to properly initialize a file stream object, leaving it in a zeroed state. This uninitialized object is then used, causing a NULL pointer dereference and resulting in a denial-of-service condition as the application crashes.
Exploitation of this vulnerability causes an access violation, leading to a crash of the PDF-XChange Editor application.
The vulnerability can be reproduced by invoking the util.readFileIntoStream method with an empty array and a maximum file size parameter. This causes the method to fail in creating a proper file stream object, which is then used while still uninitialized, triggering the NULL pointer dereference.
Users are advised to update to PDF-XChange Editor version 10.7.5.403, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.