PT-2018-14082 · Foxit · Foxit Reader+1

Published

2018-09-28

·

Updated

2018-11-14

·

CVE-2018-17610

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit PhantomPDF and Reader versions prior to 9.3
Description The issue arises from the mishandling of properties of Annotation objects, leading to potential remote code execution or denial of service due to use-after-free errors. This specifically relates to one of five distinct types of Annotation objects.
Recommendations For Foxit PhantomPDF and Reader versions prior to 9.3, update to version 9.3 or later to resolve the issue.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17610

Affected Products

Foxit Phantompdf
Foxit Reader