Skip to main content

Foxit Reader "createDataObject()" Arbitrary File Creation Vulnerability

Last Update Date: 9 Mar 2011 10:18 Release Date: 9 Mar 2011 5183 Views

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A vulnerability has been identified in Foxit Reader, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an input validation error when handling arguments supplied via the "createDataObject()" method, which could allow attackers to create a file on a vulnerable system and execute arbitrary code by tricking a user into opening a malicious PDF document.


Impact

  • Remote Code Execution

System / Technologies affected

  • Foxit Reader versions prior to 4.3.1.0218

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to Foxit Reader version 4.3.1.0218.

 


Vulnerability Identifier

  • No CVE information is available

Source


Related Link