Get a Pentest and security assessment of your IT network.

News

Deep Dive in MarkLogic Exploitation Process via Argus PDF Converter

Talos discovers and responsibly discloses software vulnerabilities on a regular basis. This blog will cover the technical aspects including discovery and exploitation process via the Argus PDF converter. MarkLogic uses this converter each time XDMP API “pdf-convert” is used. In a previous post Talos took a deep dive into Lexmark Perceptive Document Filters, in this post we are going to focus on another converter used by Marklogic located in `Converters/cvtpdf` folder. The vulnerability is a classic stack based buffer overflow, which can lead to arbitrary code execution.”]

Source: https://blog.talosintelligence.com/2017/09/deep-dive-marklogic-exploitation.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2