Foxit Reader and Phantom ICC Parsing Integer Overflow Vulnerability
Last Update Date:
28 Feb 2011 11:11
Release Date:
28 Feb 2011
6356
Views
RISK: High Risk
TYPE: Clients - Productivity Products
A vulnerability has been identified in Foxit Reader and Phantom, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an integer overflow error when parsing certain ICC chunks, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into opening a malicious file.
Impact
- Remote Code Execution
System / Technologies affected
- Foxit Reader versions 4.x
- Foxit Phantom versions 2.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Foxit Reader - Update to version 4.3.1.0218.
- Foxit Phantom - An updated version is scheduled for 28th February 2011.
Vulnerability Identifier
Source
Related Link
Share with