CERT-In Vulnerability Note
CIVN-2020-0449
Multiple Vulnerabilities in Foxit Reader and Phantom PDF
Original Issue Date:December 24, 2020
Severity Rating: HIGH
Software Affected
- Foxit Reader versions 10.1.0.37527 and earlier
- Foxit Phantom PDF versions 10.1.0.37527 and earlier
Overview
Multiple vulnerabilities have been reported in Foxit Reader and Phantom PDF which could allow a remote attacker to cause Out-of-Bounds Write Remote Code Execution, Type Confusion Memory Corruption, denial of service condition or execute arbitrary code on the target system.
Description
These vulnerabilities exist due to insufficient validation of objects, incorrect processing of PDF files, lack of proper validation when an incorrect argument is passed to the app.media.openPlayer function, access or use of a deleted pointer and array overflow issue. A remote attacker could exploit thes
CERT-IN - Computer Emergency Response Team - Page Requested Currently Not available
CERT-IN - Computer Emergency Response Team - Page Requested Currently Not available
|