Unsolved
This post is more than 5 years old
3 Apprentice
•
15.5K Posts
0
3145
October 6th, 2010 07:00
Foxit Reader Title Parsing Buffer Overflow Vulnerability
The following has been copied/pasted from http://secunia.com/advisories/41656
Description
A [highly critical] vulnerability has been discovered in Foxit Reader, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a boundary error when attempting to set the window title text and can be exploited to cause a stack-based buffer overflow via a specially crafted PDF document containing an overly long title.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is confirmed in versions 3.3.1.0518 and 4.1.1.805. Other versions may also be affected.
Solution
Update to version 4.2.0.0928, which also provides a security enhancement to the handling of PDF signatures.


