Foxit Reader Compact Font Format Memory Corruption Vulnerability
RISK: Medium Risk
A vulnerability has been identified in Foxit Reader, which could be exploited by attackers to potentially compromise a vulnerable system. This issue is caused by a memory corruption error when processing Compact Font Format (CFF) data within a PDF document, which could be exploited by attackers to potentially execute arbitrary code by tricking a user into opening a specially crafted PDF document.
Note: This vulnerability is related to the Apple iPhone jailbreakme PDF exploit. For additional information, please refer to http://www.hkcert.org/english/salert/2010/home.html?s100804_apple_ios_multi_vuln.html.
Impact
- Remote Code Execution
System / Technologies affected
- Foxit Reader versions prior to 4.1.1.0805
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Foxit Reader version 4.1.1.0805:
http://www.foxitsoftware.com/downloads/
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with