Vulnerability CVE-2011-0332


Published: 2011-02-25   Modified: 2012-02-13

Description:
Integer overflow in Foxit Reader before 4.3.1.0218 and Foxit Phantom before 2.3.3.1112 allows remote attackers to execute arbitrary code via crafted ICC chunks in a PDF file, which triggers a heap-based buffer overflow.

Vendor: Foxitsoftware
Product: Reader 
Version:
4.3
4.1.1
4.0
3.3.1
3.2.1
3.2
3.1.4
3.1.3
3.1.1
3.1
3.0
2.3
2.2
2.0
Product: Foxit reader 
Version:
4.3
4.1.1
4.0
3.3.1
3.2.1
3.2
3.1.4
3.1.3
3.1.1
3.1
3.0
2.3
2.2
2.0
Product: Foxit phantom 
Version:
2.3
2.2.4
2.2.3
2.2.1
2.2
2.1.1
2.1
2.0
1.0.2
Product: Phantom 
Version:
2.3
2.2.4
2.2.3
2.2.1
2.2
2.1.1
2.1
2.0
1.0.2

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://www.foxitsoftware.com/pdf/reader/security_bulletins.php#memory
http://www.securitytracker.com/id?1025129
http://www.vupen.com/english/advisories/2011/0508

Related CVE
CVE-2018-7407
An issue was discovered in Foxit Reader before 9.1 and PhantomPDF before 9.1. This vulnerability allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious p...
CVE-2018-7406
An issue was discovered in Foxit Reader before 9.1 and PhantomPDF before 9.1. This vulnerability allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious p...
CVE-2018-5680
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a maliciou...
CVE-2018-5679
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a maliciou...
CVE-2018-5678
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a maliciou...
CVE-2018-5677
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a maliciou...
CVE-2018-5676
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a maliciou...
CVE-2018-5675
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a maliciou...

Copyright 2018, cxsecurity.com

 

Back to Top