PT-2011-2275 · Foxit · Foxit Reader+1

Published

2011-02-25

·

Updated

2016-11-08

·

CVE-2011-0332

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Foxit Reader versions prior to 4.3.1.0218 Foxit Phantom versions prior to 2.3.3.1112
Description The issue is related to an integer overflow that can be triggered by crafted ICC chunks in a PDF file, leading to a heap-based buffer overflow. This can allow remote attackers to execute arbitrary code.
Recommendations For Foxit Reader versions prior to 4.3.1.0218, update to version 4.3.1.0218 or later. For Foxit Phantom versions prior to 2.3.3.1112, update to version 2.3.3.1112 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0332

Affected Products

Foxit Phantom
Foxit Reader