Release date: 2011-12-07
Updated on: 2011-12-08
Affected Systems:
Foxit Reader 5.1.0.1021
Foxit Reader 5.0.2.0718
Foxit Reader 5.0.1.0523
Unaffected system:
Foxit Reader 5.1.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50947
Foxit Reader is a small PDF document viewer and print program.
Foxit Reader has the array out-of-bounds access memory corruption vulnerability when processing malformed files. Remote attackers can exploit specially crafted PDF files to lure users into loading and trigger the Memory Corruption Vulnerability, this causes arbitrary code execution on the target system.
<* Source: Alex Garbutt
Link: http://www.securitytracker.com/id/1026387
Http://www.foxitsoftware.com/Secure_PDF_Reader/security_bulletins.php#termination
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Foxit
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.foxitsoft.com/wac/server_intro.php