PT-2021-17366 · Foxit · Foxit Phantompdf
Mat Powell
·
Published
2021-03-22
·
Updated
2021-04-02
·
CVE-2021-27262
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Foxit PhantomPDF version 10.1.0.37527
Description:
This issue allows remote attackers to disclose sensitive information on affected installations. User interaction is required, where the target must visit a malicious page or open a malicious file. The flaw exists within the handling of U3D objects embedded in PDF files, resulting from the lack of proper validation of user-supplied data. This can lead to a read past the end of an allocated object, potentially allowing an attacker to execute arbitrary code in the context of the current process when combined with other vulnerabilities.
Recommendations:
For Foxit PhantomPDF version 10.1.0.37527, consider disabling the handling of U3D objects embedded in PDF files as a temporary workaround until a patch is available. Restrict access to malicious pages or files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foxit Phantompdf