vendor:
Foxit Reader
by:
FuzzMyApp
7,5
CVSS
HIGH
DoS
N/A
CWE
Product Name: Foxit Reader
Affected Version From: 5.4.3.*
Affected Version To: 5.4.5.0124
Patch Exists: No
Related CWE: N/A
CPE: cpe:a:foxitsoftware:foxit_reader:5.4.5.0124
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 Professional Edition
2012
PDF Cross Reference Table parsing Denial of Service vulnerability.
Foxit Reader does not validate data in PDF Cross Reference Table (XREF) header properly. Tampering with XREF header may lead to integer division by zero exception during its parsing by the application. Raised, not handled, exception causes Denial of Service of Foxit Reader. Vendor was notified on 2013.02.21 but has not responded to this submission. This issue is present in the latest version of application avaiable at the time of writing.
Mitigation:
No mitigation available