KLA51719
Multiple vulnerabilities in Foxit PDF Reader

Обновлено: 29/09/2023
Дата обнаружения
19/07/2023
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Foxit Reader. Malicious users can exploit these vulnerabilities to obtain sensitive information, execute arbitrary code, cause denial of service, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Out of bounds read vulnerability in AcroForm can be exploited to obtain sensitive information.
  2. Use after free vulnerability in JavaScript engine can be exploited to cause denial of service or execute arbitrary code.
  3. Use after free vulnerability in Annotation can be exploited to execute arbitrary code.
  4. Type confusion vulnerability in Javascript checkThisBox method can be exploited to cause denial of service and execute arbitrary code.
  5. Use after free vulnerability in AcroForm Doc Object can be exploited to execute arbitrary code.
  6. Out of bounds read vulnerability in AcroForm signature can be exploited to execute arbitrary code.
  7. Out of bounds read vulnerability in PDF File Parsing can be exploited to obtain sensitive information.
  8. Out of bounds write vulnerability in AcroForm Doc Object can be exploited to execute arbitrary code.
  9. Use after free vulnerability in Annotation can be exploited to obtain sensitive information.
  10. Use after free vulnerability in XFA Annotation can be exploited to execute arbitrary code.
  11. Out of bounds read vulnerability in Doc Object can be exploited to obtain sensitive information.
  12. Out of bounds read vulnerability in AcroForm Doc Object can be exploited to obtain sensitive information.
Пораженные продукты

Foxit PDF Reader earlier than 12.1.3.15356

Решение

Update to the latest version
Download Foxit Reader

Первичный источник обнаружения
Security updates available in Foxit PDF Reader 12.1.3 and Foxit PDF Editor 12.1.3
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]
Связанные продукты
Foxit Reader
Foxit Reader Enterprise
CVE-IDS
CVE-2023-287445.0Warning
CVE-2023-326645.0Warning
CVE-2023-338665.0Warning
CVE-2023-338765.0Warning
CVE-2023-273795.0Warning
Узнай статистику распространения уязвимостей в твоем регионе