PT-2018-6340 · Foxit · Foxit Mobilepdf
Publicado
2018-02-26
·
Atualizado
2018-03-16
·
CVE-2017-16813
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Foxit MobilePDF versions prior to 6.1
Description:
A denial-of-service issue was discovered in the Foxit MobilePDF app. This issue occurs when a user uploads a file that includes a hexadecimal Unicode character in the
filename parameter via Wi-Fi, causing the app to fail to parse this.Recommendations:
For versions prior to 6.1, update to version 6.1 or later to resolve the issue. As a temporary workaround, consider restricting file uploads via Wi-Fi to minimize the risk of exploitation. Avoid using the
filename parameter with hexadecimal Unicode characters in the affected API endpoint until the issue is resolved.Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Foxit Mobilepdf