CVE-2008-1942: Input Validation
Foxit Reader 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with (1) a malformed ExtGState resource containing a /Font resource, or (2) an XObject resource with a Rotate setting, which triggers memory corruption. NOTE: this is probably a different vulnerability than CVE-2007-2186.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1942?
CVE-2008-1942 has a high severity due to its potential to cause a denial of service and execute arbitrary code.
How do I fix CVE-2008-1942?
To mitigate CVE-2008-1942, users should upgrade to a newer version of Foxit Reader that has addressed this vulnerability.
What systems are affected by CVE-2008-1942?
CVE-2008-1942 specifically affects Foxit Reader version 2.2.
What type of attacks can exploit CVE-2008-1942?
CVE-2008-1942 can be exploited through specially crafted PDF files that cause memory corruption.
Is CVE-2008-1942 still relevant today?
While CVE-2008-1942 is an older vulnerability, it is still relevant for users who may be using outdated versions of Foxit Reader.