CVE-2018-19347: High severity foxit reader vulnerability
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address controls Branch Selection starting at U3DBrowser!PlugInMain+0x00000000000d11bb" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19347?
CVE-2018-19347 is classified as a high severity vulnerability due to its potential to cause denial of service and leak sensitive information.
How do I fix CVE-2018-19347?
To fix CVE-2018-19347, update to the latest version of Foxit Reader or the U3D plugin that addresses this vulnerability.
Who is affected by CVE-2018-19347?
CVE-2018-19347 affects users of Foxit Reader version 9.3.0.10826 and the U3D plugin version 9.3.0.10809.
What type of attack does CVE-2018-19347 enable?
CVE-2018-19347 enables remote attackers to cause a denial of service through an out-of-bounds read.
What software is involved in CVE-2018-19347?
CVE-2018-19347 involves Foxit Reader and its U3D plugin, which are used for viewing PDF and 3D content.