KLA11093
Arbitrary code execution vulnerabilities in Foxit Reader
Обновлено: 26/06/2019
Дата обнаружения
17/08/2017
Уровень угрозы
High
Описание

Multiple serious vulnerabilities have been found in Foxit Reader and Foxit PhantomPDF. Malicious users can exploit these vulnerabilities to execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. An improper validation of user-supplied data in the saveAs Java script function can be exploited remotely via a specially designed page or file to execute arbitrary code;
  2. An improper validation of a user-supplied string before using it to execute a system call in the app.launchURL method can be exploited remotely via a specially designed page or file to execute arbitrary code.
  3. An improper validation vulnerability can be exploited remotely to execute arbitrary code.

NB: These vulnerabilities do not have any public CVSS ratings, so rating can be changed by the time.

Пораженные продукты

Foxit Reader versions through 8.3.1.21155

Решение

Update to the latest version
Download Foxit Reader
Download Foxit PhantomPDF

Первичный источник обнаружения
ZDI-17-691
ZDI-17-718
ZDI-17-692
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]
Связанные продукты
Foxit Reader
Foxit Phantom PDF
CVE-IDS