Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.107728
Category:General
Title:Foxit Software Foxit Studio Photo <= 3.6.6.779 Multiple Vulnerabilities
Summary:Foxit Studio Photo is prone to multiple vulnerabilities.
Description:Summary:
Foxit Studio Photo is prone to multiple vulnerabilities.

Vulnerability Insight:
The vulnerabilities exist due to the lack of proper validation
of user-supplied data, which can result in:

- A read past the end of an allocated structure - due to a flaw within the handling of TIF files (CVE-2019-6746)

- A write past the end of an allocated structure - due to a flaw within the handling of EZI files (CVE-2019-6747, CVE-2019-6748)

- A write past the end of an allocated structure - due to a flaw within the handling of EZIX files (CVE-2019-6749)

- A write past the end of an allocated structure - due to a flaw within the handling of EZI files (CVE-2019-6750)

- A write past the end of an allocated structure - due to a flaw within the handling of JPG files (CVE-2019-6751)

Note: User interaction is required to exploit these vulnerabilities in that the target must visit
a malicious page or open a malicious file.

Vulnerability Impact:
Successful exploitation of these vulnerabilities could allow a remote attacker
to execute arbitrary code in the context of the current process on affected installations of Foxit Studio Photo.

Affected Software/OS:
Foxit Studio Photo through version 3.6.6.779.

Solution:
Update to Foxit Studio Photo version 3.6.6.909 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-6746
https://www.foxitsoftware.com/support/security-bulletins.php
https://www.zerodayinitiative.com/advisories/ZDI-19-370/
Common Vulnerability Exposure (CVE) ID: CVE-2019-6747
https://www.zerodayinitiative.com/advisories/ZDI-19-371/
Common Vulnerability Exposure (CVE) ID: CVE-2019-6748
https://www.zerodayinitiative.com/advisories/ZDI-19-372/
Common Vulnerability Exposure (CVE) ID: CVE-2019-6749
https://www.zerodayinitiative.com/advisories/ZDI-19-373/
Common Vulnerability Exposure (CVE) ID: CVE-2019-6750
https://www.zerodayinitiative.com/advisories/ZDI-19-374/
Common Vulnerability Exposure (CVE) ID: CVE-2019-6751
https://www.zerodayinitiative.com/advisories/ZDI-19-375/
CopyrightCopyright (C) 2019 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.