CVE ID | |
CVSS SCORE | 5.1, AV:N/AC:H/Au:N/C:P/I:P/A:P |
AFFECTED VENDORS |
Foxit |
AFFECTED PRODUCTS |
Foxit Reader |
VULNERABILITY DETAILS |
The specific flaw exists within the conversion of TIFF files into PDF format. By providing a malformed TIFF, an attacker can cause Foxit Reader to read a VTable from an invalid location. This could allow an attacker to execute arbitrary code under the context of the Reader process. |
ADDITIONAL DETAILS |
Foxit has issued an update to correct this vulnerability. More details can be found at:
https://www.foxitsoftware.com/support/security-bulletins.php#FRD-31 |
DISCLOSURE TIMELINE |
|
CREDIT | Steven Seeley of Source Incite |