CVE-2012-4337: Critical severity foxit reader vulnerability
Published Aug 23, 2012
·Updated
Foxit Reader before 5.3 on Windows XP and Windows 7 allows remote attackers to execute arbitrary code via a PDF document with a crafted attachment that triggers calculation of a negative number during processing of cross references.
Affected Software
21 affected components
Foxitsoftware Foxit Reader<=5.1.4.0104
Foxitsoftware Foxit Reader=2.0
Foxitsoftware Foxit Reader=2.3
Foxitsoftware Foxit Reader=3.0
Foxitsoftware Foxit Reader=3.1.2.1013
Foxitsoftware Foxit Reader=3.1.2.1030
Foxitsoftware Foxit Reader=3.2.0.0303
Foxitsoftware Foxit Reader=3.2.1.0401
Foxitsoftware Foxit Reader=4.0
Foxitsoftware Foxit Reader=4.0.0.0619
Foxitsoftware Foxit Reader=4.1
Foxitsoftware Foxit Reader=4.1.1.0805
Foxitsoftware Foxit Reader=4.2
Foxitsoftware Foxit Reader=4.3
Foxitsoftware Foxit Reader=4.3.1.0218
Foxitsoftware Foxit Reader=5.0
Foxitsoftware Foxit Reader=5.0.2
Foxitsoftware Foxit Reader=5.1.0.1021
Foxitsoftware Foxit Reader=5.1.3
Microsoft Windows 7
Microsoft Windows XP
Event History
Aug 23, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4337?
CVE-2012-4337 is considered a high severity vulnerability due to its potential to execute arbitrary code remotely.
2
How do I fix CVE-2012-4337?
To fix CVE-2012-4337, upgrade Foxit Reader to version 5.3 or later.
3
What versions of Foxit Reader are affected by CVE-2012-4337?
CVE-2012-4337 affects Foxit Reader versions prior to 5.3, including versions 5.1.4.0104 and earlier.
4
Does CVE-2012-4337 affect Windows XP or Windows 7?
CVE-2012-4337 can be exploited on Foxit Reader running on Windows XP and Windows 7 systems.
5
What type of attack is associated with CVE-2012-4337?
CVE-2012-4337 allows remote attackers to execute arbitrary code through a crafted PDF with malicious attachments.