Foxit Reader Out-Of-Bounds Read/Write Remote Code Execution Vulnerability
Rocco Calvi
- CVSS
- 6.8
- Affected Vendors
- Foxit
- Affected Products
- Foxit Reader
Vulnerability Details
This vulnerability allows remote attackers to execute arbitrary code or disclose sensitive information on affected installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of PDF files, where the application could be exposed to an Out-of-Bounds Read or Out-of-Bounds Write vulnerability, which could lead to remote code execution or information disclosure.
Additional Details
Disclosure Timeline
- 2016-06-29 — Coordinated public release of advisory