PT-2018-16342 · Foxit · Foxit Pdf Reader

CVE-2018-3959

·

Published

2018-10-02

·

Updated

2023-02-02

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit PDF Reader version 9.1.0.5096
Description A use-after-free issue exists in the JavaScript engine. This can occur when accessing the Author property of the this.info object. An attacker can trigger this by tricking a user into opening a malicious file. If the browser plugin extension is enabled, visiting a malicious site can also trigger the issue.
Recommendations For Foxit PDF Reader version 9.1.0.5096, consider disabling the JavaScript engine or the browser plugin extension as a temporary workaround until a patch is available. Avoid opening files from untrusted sources to minimize the risk of exploitation.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-3959

Affected Products

Foxit Pdf Reader