First published: Tue Mar 10 2009(Updated: )
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) absolute path in the filename argument in an action, as demonstrated by the "Open/Execute a file" action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit PDF Reader for Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0837 has been classified as a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2009-0837, users should upgrade to Foxit Reader version 3.0 Build 1506 or later.
CVE-2009-0837 is a stack-based buffer overflow vulnerability.
CVE-2009-0837 affects Foxit Reader version 3.0 prior to Build 1506.
Yes, CVE-2009-0837 can be exploited remotely through specially crafted filenames in an action.