Skip to main content

Foxit Reader Compact Font Format Memory Corruption Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 9 Aug 2010 4350 Views

RISK: Medium Risk

A vulnerability has been identified in Foxit Reader, which could be exploited by attackers to potentially compromise a vulnerable system. This issue is caused by a memory corruption error when processing Compact Font Format (CFF) data within a PDF document, which could be exploited by attackers to potentially execute arbitrary code by tricking a user into opening a specially crafted PDF document.

Note: This vulnerability is related to the Apple iPhone jailbreakme PDF exploit. For additional information, please refer to http://www.hkcert.org/english/salert/2010/home.html?s100804_apple_ios_multi_vuln.html.


Impact

  • Remote Code Execution

System / Technologies affected

  • Foxit Reader versions prior to 4.1.1.0805

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link