First published: Mon Dec 24 2018(Updated: )
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref entries using the DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.
Credit: cve@checkpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Quick PDF Library | <16.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20249 is considered a critical vulnerability as it can lead to access violations due to out-of-bounds memory access.
To fix CVE-2018-20249, users should upgrade to Foxit Quick PDF Library version 16.12 or later.
CVE-2018-20249 affects all versions of Foxit Quick PDF Library prior to 16.12.
Exploiting CVE-2018-20249 can cause an application crash due to access violations when processing malformed PDFs.
The DAOpenFile and DAOpenFileReadOnly functions are vulnerable to CVE-2018-20249 when loading malformed PDFs.