SB2016070505 - Multiple vulnerabilities in Foxit Reader and PhantomPDF



SB2016070505 - Multiple vulnerabilities in Foxit Reader and PhantomPDF

Published: July 5, 2016

Security Bulletin ID SB2016070505
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Out-of-bounds write (CVE-ID: N/A)

The vulnerability allows remote attacker to execute arbitrary code on vulnerable installations of Foxit Reader.

The vulnerability exists within the ConvertToPDF plugin. A remote attacker can cause arbitrary code execution by sending specially crafted GIF image to vulnerable server.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

2) Improper input validation (CVE-ID: N/A)

The vulnerability allow a remote attacker to execute arbitrary code on vulnerable installations of Foxit Reader.

The vulnerability exists within the ConvertToPDF plugin. A remote unauthenticated attacker can cause remote code execution by sending specially crafted JPEG image to vulnerable server.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Remediation

Install update from vendor's website.