PT-2011-3469 · Foxit+1 · Foxit Reader+1

Published

2011-06-24

·

Updated

2017-08-17

·

CVE-2011-1908

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Foxit Reader versions prior to 4.0.0.0619
Description The issue is related to an integer overflow in the Type 1 font decoder in the FreeType engine, which can be exploited by remote attackers. This can be achieved by using a crafted font in a PDF document, potentially allowing the execution of arbitrary code or causing a denial of service, resulting in an application crash.
Recommendations For versions prior to 4.0.0.0619, update to version 4.0.0.0619 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1908

Affected Products

Foxit Reader
Freetype