CVE-2011-0332: Buffer Overflow
Published Feb 25, 2011
·Updated
Integer overflow in Foxit Reader before 4.3.1.0218 and Foxit Phantom before 2.3.3.1112 allows remote attackers to execute arbitrary code via crafted ICC chunks in a PDF file, which triggers a heap-based buffer overflow.
Affected Software
23 affected components
Foxitsoftware Foxit Reader<=4.3
Foxitsoftware Foxit Reader=2.0
Foxitsoftware Foxit Reader=2.2
Foxitsoftware Foxit Reader=2.3
Foxitsoftware Foxit Reader=3.0
Foxitsoftware Foxit Reader=3.1
Foxitsoftware Foxit Reader=3.1.1
Foxitsoftware Foxit Reader=3.1.3
Foxitsoftware Foxit Reader=3.1.4
Foxitsoftware Foxit Reader=3.2
Foxitsoftware Foxit Reader=3.2.1
Foxitsoftware Foxit Reader=3.3.1
Foxitsoftware Foxit Reader=4.0
Foxitsoftware Foxit Reader=4.1.1
Foxitsoftware Foxit Phantom<=2.3
Foxitsoftware Foxit Phantom=1.0.2
Foxitsoftware Foxit Phantom=2.0
Foxitsoftware Foxit Phantom=2.1
Foxitsoftware Foxit Phantom=2.1.1
Foxitsoftware Foxit Phantom=2.2
Foxitsoftware Foxit Phantom=2.2.1
Foxitsoftware Foxit Phantom=2.2.3
Foxitsoftware Foxit Phantom=2.2.4
Remediation
Event History
Feb 25, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What type of attack does CVE-2011-0332 enable?
CVE-2011-0332 allows remote attackers to execute arbitrary code via crafted ICC chunks in a PDF file.