CVE-2018-5675: High severity Foxitsoftware Phantompdf vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of specially crafted pdf files with embedded u3d images. Crafted data in the PDF file can trigger an out-of-bounds write on a buffer. An attacker can leverage this vulnerability to execute code under the context of the current process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Foxit Readerto a version that resolves this vulnerability.Fixed in 9.1 - Upgrade
Upgrade
PhantomPDFto a version that resolves this vulnerability.Fixed in 9.1 - Compensating control
Since user interaction is required (victim must visit a malicious page or open a malicious file), restrict users from opening untrusted PDF files and visiting untrusted web pages, and use email/web filtering to block malicious documents and links.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5675?
CVE-2018-5675 has a high severity due to its potential for remote code execution.
How do I fix CVE-2018-5675?
To fix CVE-2018-5675, upgrade Foxit Reader and PhantomPDF to versions 9.1 or higher.
Who is affected by CVE-2018-5675?
CVE-2018-5675 affects users of Foxit Reader and PhantomPDF versions prior to 9.1.
What type of attack exploits CVE-2018-5675?
CVE-2018-5675 can be exploited through user interaction with a malicious file or web page.
Which software versions are vulnerable to CVE-2018-5675?
Vulnerable versions of Foxit Reader and PhantomPDF are those up to and including 9.0.1.1049.