KLA12028
Multiple vulnerabilities in Foxit Reader and Foxit PhantomPDF

Обновлено: 16/12/2020
Дата обнаружения
09/12/2020
Уровень угрозы
Warning
Описание

Multiple vulnerabilities were found in Foxit Reader and Foxit PhantomPDF. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability in PDF file can be exploited remotely to execute arbitrary code and cause denial of service.
  2. A denial of service vulnerability in PDF file can be exploited to potentially cause denial of service.
  3. Memory corruption vulnerability in PDF JavaScript API can be exploited renotely to execute arbitrary code or cause denial of service.
  4. Out of bounds write vulnerability in XFA templates can be exploited remotely to execute arbitrary code and cause denial of service.
Пораженные продукты

Foxit Reader earlier than 10.1.1.37576
Foxit PhantomPDF earlier than 10.1.1.37576

Решение

Update to the latest version
Download Foxit Reader

Первичный источник обнаружения
Foxit Security Bulletins
Оказываемое влияние
?
ACE 
[?]

DoS 
[?]
Связанные продукты
Foxit Reader
Foxit Phantom PDF
CVE-IDS
CVE-2020-135600.0Unknown
CVE-2020-135700.0Unknown
CVE-2020-135480.0Unknown
CVE-2020-282030.0Unknown
CVE-2020-135470.0Unknown
CVE-2020-135570.0Unknown
CVE-2020-278600.0Unknown