CVE-2009-0191: Code Injection
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 3.0.2009.1301, does not properly handle a JBIG2 symbol dictionary segment with zero new symbols, which allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a dereference of an uninitialized memory location.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0191?
CVE-2009-0191 has a critical severity level as it allows remote code execution.
How do I fix CVE-2009-0191?
To fix CVE-2009-0191, update Foxit Reader to version 3.0.2009.1301 or later.
What versions of Foxit Reader are affected by CVE-2009-0191?
CVE-2009-0191 affects Foxit Reader version 2.3 prior to Build 3902 and version 3.0 prior to Build 1506.
What type of vulnerability is CVE-2009-0191?
CVE-2009-0191 is a vulnerability that involves improper handling of JBIG2 symbol dictionary segments.
Can CVE-2009-0191 be exploited without user interaction?
Yes, CVE-2009-0191 can be exploited through a crafted PDF file, enabling remote attackers to execute arbitrary code.