PT-2022-17428 · Foxit · Foxit Pdf Reader+2

Published

2022-05-09

·

Updated

2022-09-02

·

CVE-2022-25641

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Foxit PDF Reader versions prior to 11.2.2 PDF Editor versions prior to 11.2.2 PhantomPDF versions prior to 10.1.8
Description The issue arises from the mishandling of cross-reference information during compressed-object parsing within signed documents. This leads to the delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack. The parsing engine fails to use the cross-reference information correctly when parsing certain compressed objects, resulting in a parsing error.
Recommendations For Foxit PDF Reader versions prior to 11.2.2, update to version 11.2.2 or later to resolve the issue. For PDF Editor versions prior to 11.2.2, update to version 11.2.2 or later to resolve the issue. For PhantomPDF versions prior to 10.1.8, update to version 10.1.8 or later to resolve the issue. As a temporary workaround, consider avoiding the use of signed PDF files until a patch is available.

Fix

Related Identifiers

CVE-2022-25641

Affected Products

Foxit Pdf Reader
Pdf Editor
Phantompdf