DjVu.ImageURL.Property.ActiveX.Control.Access

description-logoDescription

This indicates an attempt to exploit a buffer-overflow vulnerability in DjVu.
This vulnerability is due to a program error that leads to a buffer overflow in the "DjVu_ActiveX_MSOffice.dll" ActiveX control. The overflow occurs when processing an overly long argument passed to the "ImageURL" property. A remote attacker may exploit this to execute arbitrary code.

affected-products-logoAffected Products

Any version of DjVu

Impact logoImpact

System Compromise.

recomended-action-logoRecommended Actions

Currently we are not aware of any vendor-supplied patch for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-07-22 15.892 Sig Added
2020-07-14 15.885 Sig Added