KLA12028
Multiple vulnerabilities in Foxit Reader and Foxit PhantomPDF

Updated: 12/16/2020
Detect date
?
12/09/2020
Severity
?
Warning
Description

Multiple vulnerabilities were found in Foxit Reader and Foxit PhantomPDF. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability in PDF file can be exploited remotely to execute arbitrary code and cause denial of service.
  2. A denial of service vulnerability in PDF file can be exploited to potentially cause denial of service.
  3. Memory corruption vulnerability in PDF JavaScript API can be exploited renotely to execute arbitrary code or cause denial of service.
  4. Out of bounds write vulnerability in XFA templates can be exploited remotely to execute arbitrary code and cause denial of service.
Affected products

Foxit Reader earlier than 10.1.1.37576
Foxit PhantomPDF earlier than 10.1.1.37576

Solution

Update to the latest version
Download Foxit Reader

Original advisories

Foxit Security Bulletins

Impacts
?
ACE 
[?]

DoS 
[?]
Related products
Foxit Reader
Foxit Phantom PDF
CVE-IDS
?
CVE-2020-135600.0Unknown
CVE-2020-135700.0Unknown
CVE-2020-135480.0Unknown
CVE-2020-282030.0Unknown
CVE-2020-135470.0Unknown
CVE-2020-135570.0Unknown
CVE-2020-278600.0Unknown