CVE-2022-24954
Summary
| CVE | CVE-2022-24954 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-11 02:15:00 UTC |
| Updated | 2022-02-17 03:27:00 UTC |
| Description | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| www.foxit.com/support/security-bulletins.html |
MISC |
www.foxit.com |
|
| DoHyun Lee on Twitter: "Foxit PDF Reader Stack-Based Buffer Overflow
A Stack Buffer Overflow vulnerability occurs due to a specific defect in the XFA Form.
PoC Code
```
"""
<subform colSpan="-2" />
<draw colSpan="1"/>
"""
```" |
MISC |
twitter.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376764 Foxit Reader and Foxit PDF Editor Prior to 11.2.1 Multiple Security Vulnerabilities
- 376802 Foxit PhantomPDF Prior to 10.1.7 Multiple Security Vulnerabilities