First published: Wed May 21 2008(Updated: )
Stack-based buffer overflow in Foxit Reader before 2.3 build 2912 allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file, related to the util.printf JavaScript function and floating point specifiers in format strings.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader | <=2.3 | |
Foxit Reader | =2.0 | |
Foxit Reader | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1104 has a high severity level due to its potential to allow remote code execution.
To fix CVE-2008-1104, upgrade to Foxit Reader version 2.3 build 2912 or later.
CVE-2008-1104 affects Foxit Reader versions up to and including 2.3, specifically versions 2.0 and 2.2.
CVE-2008-1104 is a stack-based buffer overflow vulnerability.
CVE-2008-1104 can be exploited by remote attackers through a maliciously crafted PDF file.