CVE-2017-8059: High severity Foxitsoftware Foxit Pdf Iphone Os vulnerability
Published May 5, 2017
·Updated
Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addition to the static authentication token if the user is already logged in.
Affected Software
2 affected components
Foxitsoftware Foxit Pdf Iphone Os=5.2.1
Foxitsoftware Foxit Pdf Iphone Os=5.3.2
Event History
May 5, 2017
CVE Published
via MITRE·07:04 AM
Data Sourced
via MITRE·07:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8059?
CVE-2017-8059 has a high severity rating of 8.1.
2
How do I fix CVE-2017-8059?
To fix CVE-2017-8059, upgrade to the latest version of Foxit PDF that addresses this vulnerability.
3
What versions of Foxit PDF are affected by CVE-2017-8059?
CVE-2017-8059 affects Foxit PDF versions 5.2.1 and 5.3.2 for iOS.
4
What type of vulnerability is CVE-2017-8059?
CVE-2017-8059 is a vulnerability that involves the acceptance of invalid or self-signed TLS certificates.
5
What are the potential impacts of CVE-2017-8059?
CVE-2017-8059 allows attackers to silently intercept login information and static authentication tokens.