Executive brief
Foxit Reader and PhantomPDF are popular applications used to view and edit PDF documents. A vulnerability in the JPEG image processing component allows an attacker to crash the application or potentially steal sensitive information if a user opens a specially crafted file. This could lead to a loss of productivity due to service disruption or be used as a stepping stone for further unauthorized access to the user's system.
Technical details
An out-of-bounds read vulnerability exists in the ConvertToPDF plugin of Foxit Reader and PhantomPDF when processing JPEG images. The flaw is triggered when the application fails to properly validate user-supplied data within a JPEG file, leading to a read past the end of an allocated buffer. While the primary impact is an application crash (denial of service), the out-of-bounds read can also result in the disclosure of sensitive memory information. An attacker could potentially chain this with other vulnerabilities to achieve remote code execution. Exploitation requires a user to open a malicious JPEG or visit a page containing one. The issue is addressed in version 8.2.
Affected products
- Foxit Foxit Reader Before 8.2
- Foxit PhantomPDF Before 8.2
Timeline
- 2016-12-01: disclosed: Vulnerability reported to vendor
- 2017-01-11: patched: Coordinated public release of advisory and fix in version 8.2
- 2017-01-23: advisory: NVD published date