Vulnerabilities > CVE-2011-1908 - Numeric Errors vulnerability in Foxitsoftware Foxit Reader
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Integer overflow in the Type 1 font decoder in the FreeType engine in Foxit Reader before 4.0.0.0619 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font in a PDF document.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | Windows |
NASL id | FOXIT_READER_4_0_0_0619.NASL |
description | The version of Foxit Reader installed on the remote Windows host is prior to 4.0.0.0619. It is, therefore, affected by a remote code execution vulnerability in the FreeType engine due to an integer overflow condition in the Type 1 font decoder. An attacker can exploit this, by tricking a user into opening a crafted PDF file, to cause a denial of service or to execute arbitrary code with the user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 55422 |
published | 2011-06-24 |
reporter | This script is Copyright (C) 2011-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/55422 |
title | Foxit Reader < 4.0.0.0619 FreeType Engine RCE |
code |
|
Seebug
bulletinFamily | exploit |
description | Bugtraq ID: 48359 CVE ID:CVE-2011-1908 Foxit Reader是一款流行的处理PDF文件的应用程序。 Foxit Reader处理某些非法字体类型存在可利用漏洞,攻击者可以利用这个漏洞使Foxit Reader非正常退出,允许攻击者执行任意代码。 Foxit Foxit Reader 3.2.1 0401 Foxit Foxit Reader 3.2 0303 Foxit Foxit Reader 3.0.2009 .1301 Foxit Foxit Reader 4.0 Foxit Foxit Reader 3.3.1.0518 Foxit Foxit Reader 3.2 Foxit Foxit Reader 3.1.4.1125 Foxit Foxit Reader 3.0 Build 1817 Foxit Foxit Reader 3.0 Build 1506 Foxit Foxit Reader 3.0 Foxit Foxit Reader 2.3 Build 3902 Foxit Foxit Reader 2.3 build 2923 Foxit Foxit Reader 2.3 build 2825 Foxit Foxit Reader 2.3 Foxit Foxit Reader 2.2 厂商解决方案 Foxit Reader 4.0.0.0619已经修复此漏洞,建议用户下载使用: http://www.foxitsoftware.com/pdf/reader/ |
id | SSV:20661 |
last seen | 2017-11-19 |
modified | 2011-06-25 |
published | 2011-06-25 |
reporter | Root |
title | Foxit Reader Freetype引擎远程整数溢出漏洞 |
References
- http://www.foxitsoftware.com/products/reader/security_bulletins.php#freetype
- http://www.microsoft.com/technet/security/advisory/msvr11-005.mspx
- http://www.securityfocus.com/bid/48359
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68145
- http://www.foxitsoftware.com/products/reader/security_bulletins.php#freetype
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68145
- http://www.securityfocus.com/bid/48359
- http://www.microsoft.com/technet/security/advisory/msvr11-005.mspx