Skip to main content

Foxit Reader and Phantom ICC Parsing Integer Overflow Vulnerability

Last Update Date: 28 Feb 2011 11:11 Release Date: 28 Feb 2011 6356 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

 

A vulnerability has been identified in Foxit Reader and Phantom, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an integer overflow error when parsing certain ICC chunks, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into opening a malicious file.


Impact

  • Remote Code Execution

System / Technologies affected

  • Foxit Reader versions 4.x
  • Foxit Phantom versions 2.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Foxit Reader - Update to version 4.3.1.0218.
  • Foxit Phantom - An updated version is scheduled for 28th February 2011.

Vulnerability Identifier


Source


Related Link