Memory leak in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF) - #VU4396
Published: January 12, 2017
Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to boundary error when processing fonts within PDF files. A remote attacker can create a specially rafted PDF file, trick the victim into opening it, trigger out-of-bounds read and gain access to potentially sensitive information, stored in memory.
Successful exploitation of this vulnerability may allow an attacker to gain access to potentially sensitive data.