Executive brief
Foxit PDF Toolkit is a set of tools used by developers and businesses to process and manipulate PDF documents. A security flaw in version 1.3 allows an attacker to take control of a computer or crash the software if a user is tricked into opening a specially crafted PDF file. This could lead to the theft of sensitive information or a disruption of business operations.
Technical details
A memory corruption vulnerability (CWE-119) exists in Foxit PDF Toolkit v1.3 due to improper restriction of operations within the bounds of a memory buffer. The vulnerability is triggered when the application processes a specially crafted PDF file. An attacker can exploit this by convincing a user to open the malicious file, potentially leading to arbitrary code execution or a denial-of-service (DoS) condition. The attack vector is local with a requirement for user interaction (UI:R). The issue has been addressed in version 2.0.
Affected products
- Foxit PDF Toolkit 1.3
Timeline
- 2017-01-13: disclosed
- 2017-01-13: advisory
- 2017-01-13: patched: Fixed in version 2.0