| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.801313 |
| Category: | General |
| Title: | Foxit Reader Arbitrary Command Execution Vulnerability |
| Summary: | Check for the version of Foxit Reader |
| Description: | Overview: The host is installed with Foxit Reader and is prone to arbitrary command execution vulnerability. Vulnerability Insight: The flaw exists due to error in hadling 'PDF' files which runs executable embedded program inside a PDF automatically without asking for user permission. Impact: Successful exploitation will let attacker to execute arbitrary code or crash an affected application. Impact Level: Application Affected Software/OS: Foxit Reader version prior to 3.2.1.0401 Fix: Upgrade to the version 3.2.1.0401 or later, For updates refer to http://www.foxitsoftware.com/downloads/ References: http://www.kb.cert.org/vuls/id/570177 http://www.foxitsoftware.com/pdf/reader/security.htm#0401 http://blog.didierstevens.com/2010/03/29/escape-from-pdf/ http://blog.didierstevens.com/2010/03/31/escape-from-foxit-reader/ |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-1239 http://blog.didierstevens.com/2010/03/29/escape-from-pdf/ http://blog.didierstevens.com/2010/03/31/escape-from-foxit-reader/ http://www.f-secure.com/weblog/archives/00001923.html CERT/CC vulnerability note: VU#570177 http://www.kb.cert.org/vuls/id/570177 |
| Copyright | Copyright (c) 2010 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|