Searching
..

Click anywhere to stop

KLA12028
Multiple vulnerabilities in Foxit Reader and Foxit PhantomPDF

Обновлено: 25/01/2024
Дата обнаружения
09/12/2020
Уровень угрозы
Warning
Описание

Multiple vulnerabilities were found in Foxit Reader and Foxit PhantomPDF. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability in PDF file can be exploited remotely to execute arbitrary code and cause denial of service.
  2. A denial of service vulnerability in PDF file can be exploited to potentially cause denial of service.
  3. Memory corruption vulnerability in PDF JavaScript API can be exploited renotely to execute arbitrary code or cause denial of service.
  4. Out of bounds write vulnerability in XFA templates can be exploited remotely to execute arbitrary code and cause denial of service.
Пораженные продукты

Foxit Reader earlier than 10.1.1.37576
Foxit PhantomPDF earlier than 10.1.1.37576

Решение

Update to the latest version
Download Foxit Reader

Первичный источник обнаружения
Foxit Security Bulletins
Оказываемое влияние
?
ACE 
[?]

DoS 
[?]

SB 
[?]
Связанные продукты
Foxit Reader
Foxit Phantom PDF
CVE-IDS
CVE-2020-135608.8Critical
CVE-2020-135708.8Critical
CVE-2020-135488.8Critical
CVE-2020-282035.5High
CVE-2020-135478.8Critical
CVE-2020-135578.8Critical
CVE-2020-278607.8Critical
Узнай статистику распространения уязвимостей в твоем регионе