Foxit Reader 'FoxitReaderOCX' ActiveX Control 'OpenFile()' Buffer Overflow Vulnerability
BID:48836
Info
Foxit Reader 'FoxitReaderOCX' ActiveX Control 'OpenFile()' Buffer Overflow Vulnerability
| Bugtraq ID: | 48836 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2011 12:00AM |
| Updated: | Jul 21 2011 12:00AM |
| Credit: | Secunia Research |
| Vulnerable: |
Foxit Foxit Reader 5.0.1.0523 |
| Not Vulnerable: |
Foxit Foxit Reader 5.0.2.0718 |
Discussion
Foxit Reader 'FoxitReaderOCX' ActiveX Control 'OpenFile()' Buffer Overflow Vulnerability
Foxit Reader is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using an affected ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Foxit Reader 5.0.1.0523 is vulnerable; other versions may also be affected.
Foxit Reader is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using an affected ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Foxit Reader 5.0.1.0523 is vulnerable; other versions may also be affected.
Exploit / POC
Foxit Reader 'FoxitReaderOCX' ActiveX Control 'OpenFile()' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Foxit Reader 'FoxitReaderOCX' ActiveX Control 'OpenFile()' Buffer Overflow Vulnerability
Solution:
The vendor released an update please see the references for details.
Solution:
The vendor released an update please see the references for details.
References
Foxit Reader 'FoxitReaderOCX' ActiveX Control 'OpenFile()' Buffer Overflow Vulnerability
References:
References:
- Foxit Reader Homepage (Foxit )
- Secunia Research: Foxit Reader ActiveX Control OpenFile() Buffer Overflow Vulner (Secunia Research)