CERT-In Vulnerability Note
CIVN-2023-0001
Multiple Vulnerabilities in Foxit Products
Original Issue Date:January 02, 2023
Severity Rating: HIGH
Software Affected
- Foxit PhantomPDF version 10.1.9.37808 and earlier
- Foxit PDF Editor version 11.2.3.53593 and all previous 11.x versions
- Foxit PDF Editor version 10.1.9.37808 and earlier
Overview
Multiple vulnerabilities have been reported in Foxit PDF Reader and Editor which could allow an attacker to execute remote code, disclose information and cause a denial of service on the targeted system.
Description
These vulnerabilities exist due to the use of object or pointer that has been freed when executing certain JavaScripts in PDF files, array access violation when handling certain PDF files containing a field that is formatted as ¿Percent¿ with an overly large value, the infinite recursion resulting from the self-referenced object or incorrect hierarchy structure of nodes when handling certain PDF or XFA files, use of null pointer without proper validation when parsing certain PDF files that contain the invalid Page object, access of the array outside the bounds resulting from the logic error when parsing certain PDF files whose colSpan attribute is set beyond the maximum length allowed.
Successful exploitation of these vulnerabilities could allow an attacker to execute remote code, disclose information and cause a denial of service on the targeted system.
Solution
Upgrade to the latest version of Foxit PhantomPDF and PDF Editor:
https://www.foxitsoftware.com/support/security-bulletins.html
Vendor Information
Foxit Software
https://www.foxitsoftware.com/support/security-bulletins.html
References
Foxit Software
https://www.foxitsoftware.com/support/security-bulletins.html
CVE Name
CVE-2022-43637
CVE-2022-43638
CVE-2022-43639
CVE-2022-43640
CVE-2022-43641
CVE-2022-32774
CVE-2022-38097
CVE-2022-37332
CVE-2022-40129
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|