Foxit Reader/PhantomPDF post-release Reuse Vulnerability (CVE-2015-8580)
Foxit Reader/PhantomPDF post-release Reuse Vulnerability (CVE-2015-8580)
Release date:
Updated on:
Affected Systems:
Foxit Reader <7.2.2
Foxit Phantom PDF <7.2.2
Description:
CVE (CAN) ID: CVE-2015-8580
Foxit PhantomPDF is a set of practical PDF solutions.
In versions earlier than Foxit Reader 7.2.2 and earlier than Foxit PhantomPDF 7.2.2, multiple post-release reuse vulnerabilities exist in Print objects and App object processing. Remote attackers exploit the constructed PDF files, attackers can execute arbitrary code.
<* Source: AbdulAziz harsiri
*>
Suggestion:
Vendor patch:
Foxit
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.foxitsoftware.com/support/security-bulletins.php#FRD-34
Refer:
Http://www.zerodayinitiative.com/advisories/ZDI-15-623
Http://www.zerodayinitiative.com/advisories/ZDI-15-622
This article permanently updates the link address: