Information disclosure in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF) - CVE-2018-17781

 

Information disclosure in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF) - CVE-2018-17781

Published: September 30, 2018


Vulnerability identifier: #VU15046
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17781
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to uninitialized object disclosure error when creating ArrayBuffer and DataView objects within PDF files. A remote attacker can create a specially crafted PDF file, trick the victim into opening it and gain access to sensitive information.



Affected software

Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)

How to mitigate CVE-2018-17781

Install updates from vendor's website.

Foxit PDF Reader for Windows - update to 9.3
Foxit PDF Editor (formerly Foxit PhantomPDF) - update to 9.3

External References

Related Security Bulletins