Foxit Reader 'util.printf()' Remote Buffer Overflow Vulnerability
BID:29288
Info
Foxit Reader 'util.printf()' Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 29288 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1104 |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2008 12:00AM |
| Updated: | May 27 2008 10:04PM |
| Credit: | Dyon Balding, Secunia Research |
| Vulnerable: |
Foxit Foxit Reader 2.3 build 2825 |
| Not Vulnerable: |
Foxit Foxit Reader 2.3 build 2923 |
Discussion
Foxit Reader 'util.printf()' Remote Buffer Overflow Vulnerability
Foxit Reader is prone to a remote buffer-overflow vulnerability when handling PDF files with specially crafted JavaScript code.
Exploiting this issue may allow attackers to corrupt memory and execute arbitrary machine code in the context of users running the affected application. Failed exploits will likely cause denial-of-service conditions.
This issue affects Foxit Reader 2.3 build 2825; other versions may also be affected.
Foxit Reader is prone to a remote buffer-overflow vulnerability when handling PDF files with specially crafted JavaScript code.
Exploiting this issue may allow attackers to corrupt memory and execute arbitrary machine code in the context of users running the affected application. Failed exploits will likely cause denial-of-service conditions.
This issue affects Foxit Reader 2.3 build 2825; other versions may also be affected.
Exploit / POC
Foxit Reader 'util.printf()' Remote Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Foxit Reader 'util.printf()' Remote Buffer Overflow Vulnerability
Solution:
The vendor has released fixes. Please contact the vendor for information on obtaining and applying the updates.
Solution:
The vendor has released fixes. Please contact the vendor for information on obtaining and applying the updates.
References
Foxit Reader 'util.printf()' Remote Buffer Overflow Vulnerability
References:
References:
- Foxit Reader Homepage (Foxit )
- Security Release - Foxit Reader V2.3 Build 2923 (Foxit)
- Secunia Research: Foxit Reader "util.printf()" Buffer Overflow (Secunia Research
) - Secunia Research: Foxit Reader util.printf() Buffer Overflow (Secunia Research)
- Vulnerability Note VU#119747 (US-CERT)