First published: Mon Apr 05 2010(Updated: )
Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF document via an unspecified "/Launch /Action" sequence, a related issue to CVE-2009-0836.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader | <=3.2.0.0303 | |
Foxit Reader | =2.3 | |
Foxit Reader | =3.0 | |
Foxit Reader | =3.1.0.0824 | |
Foxit Reader | =3.1.1.0901 | |
Foxit Reader | =3.1.1.0928 | |
Foxit Reader | =3.1.3.1030 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1239 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2010-1239, update Foxit Reader to version 3.2.1.0401 or later.
CVE-2010-1239 affects all versions of Foxit Reader prior to 3.2.1.0401.
CVE-2010-1239 allows remote attackers to execute arbitrary local programs through specially crafted PDF files.
As a workaround for CVE-2010-1239, users can disable JavaScript in Foxit Reader to mitigate risks until a patch is applied.