CVE-2021-33792: High severity foxit reader vulnerability
Published Jul 9, 2021
·Updated
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trailer dictionary.
Affected Software
2 affected components
Foxitsoftware Foxit Reader<10.1.4
Foxitsoftware Phantompdf<10.1.4
Event History
Jul 9, 2021
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
Description
Frequently Asked Questions
1
What is CVE-2021-33792?
CVE-2021-33792 is a vulnerability that exists in Foxit Reader and PhantomPDF versions before 10.1.4.
2
How severe is CVE-2021-33792?
CVE-2021-33792 has a severity rating of 7.8, which is considered high.
3
How does CVE-2021-33792 affect Foxit Reader and PhantomPDF?
CVE-2021-33792 allows an attacker to perform an out-of-bounds write via a crafted /Size key in the Trailer dictionary.
4
Which versions of Foxit Reader and PhantomPDF are affected by CVE-2021-33792?
Foxit Reader and PhantomPDF versions before 10.1.4 are affected by CVE-2021-33792.
5
How can I fix CVE-2021-33792?
To fix CVE-2021-33792, it is recommended to update Foxit Reader and PhantomPDF to version 10.1.4 or above.