Foxit PhantomPDF after The ListBox value is released, the remote code execution vulnerability is reused.
Foxit PhantomPDF after The ListBox value is released, the remote code execution vulnerability is reused.
Release date:
Updated on:
Affected Systems:
Foxit Reader <= 7.3.0.118
Foxit Phantom PDF <= 7.3.0.118
Description:
CVE (CAN) ID:
PhantomPDF is a general PDF editor.
PhantomPDF has a security vulnerability in processing the value attribute of ListBox, which can be reused by releasing a pointer. attackers can execute arbitrary code in the context of the current process.
<* Source: AbdulAziz harsiri
*>
Suggestion:
Vendor patch:
Foxit
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.foxitsoftware.com/support/security-bulletins.php
This article permanently updates the link address: