SB2017070517 - Input validation error in WinDjView



SB2017070517 - Input validation error in WinDjView

Published: July 5, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017070517
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2017-7894)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

WinDjView 2.1 might allow user-assisted attackers to execute code via a crafted .djvu file, because of a "User Mode Write AV near NULL" in WinDjView.exe. One threat model is a victim who obtains an untrusted .djvu file from a remote location and issues several user-defined commands.


Remediation

Install update from vendor's website.