CVE-2009-0836: Buffer Overflow
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0836?
CVE-2009-0836 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2009-0836?
To fix CVE-2009-0836, upgrade to Foxit Reader version 2.3 Build 3902 or 3.0 Build 1506 or later.
Which versions of Foxit Reader are affected by CVE-2009-0836?
CVE-2009-0836 affects Foxit Reader versions 2.3 prior to Build 3902 and 3.0 prior to Build 1506.
What types of attacks can CVE-2009-0836 facilitate?
CVE-2009-0836 can facilitate arbitrary code execution by allowing attackers to execute programs through malicious PDF files.
What actions does CVE-2009-0836 allow without user confirmation?
CVE-2009-0836 allows dangerous actions defined in a PDF file to be executed without user confirmation.