CVE-2010-1239: Code Injection
Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF document via an unspecified "/Launch /Action" sequence, a related issue to CVE-2009-0836.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1239?
CVE-2010-1239 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2010-1239?
To fix CVE-2010-1239, update Foxit Reader to version 3.2.1.0401 or later.
Who is affected by CVE-2010-1239?
CVE-2010-1239 affects all versions of Foxit Reader prior to 3.2.1.0401.
What types of attacks are possible with CVE-2010-1239?
CVE-2010-1239 allows remote attackers to execute arbitrary local programs through specially crafted PDF files.
Is there a workaround for CVE-2010-1239?
As a workaround for CVE-2010-1239, users can disable JavaScript in Foxit Reader to mitigate risks until a patch is applied.