An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory condition which isn't handled properly, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HFoxitsoftware Phantompdf
APPFoxitsoftware≤ 9.4.1.16828Foxitsoftware Reader
APPFoxitsoftware≤ 9.4.1.16828
Related vulnerabilities
Uszkodzenie pamięci podczas konwersji PDF w Foxit Reader i PhantomPDF
Foxit Reader/PhantomPDF: usuwanie plików przez atak symlink
Zapis poza granicami bufora w Foxit Reader i PhantomPDF przy konwersji dokumentów Office
Foxit Reader i PhantomPDF — ujawnienie danych lub crash przy obsłudze XFA
Foxit Reader/PhantomPDF — zapis do dowolnych plików przez brak walidacji ścieżki extractPages