CVE-2021-33793: Critical severity foxit reader vulnerability
Published Aug 11, 2021
·Updated
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.
Affected Software
2 affected components
Foxitsoftware Foxit Reader<10.1.4
Foxitsoftware Phantompdf<10.1.4
Remediation
Event History
Aug 11, 2021
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue in Foxit Reader and PhantomPDF?
The vulnerability ID for this security issue in Foxit Reader and PhantomPDF is CVE-2021-33793.
2
What is the severity of CVE-2021-33793?
The severity of CVE-2021-33793 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software includes Foxit Reader versions up to 10.1.4 and PhantomPDF versions up to 10.1.4.
4
How does the vulnerability in Foxit Reader and PhantomPDF occur?
The vulnerability in Foxit Reader and PhantomPDF is caused by an out-of-bounds write during Office document conversion due to mishandling of the Cross-Reference table.
5
Is there a fix available for CVE-2021-33793?
Yes, a fix is available for CVE-2021-33793. Users should update to Foxit Reader version 10.1.4 or later, or PhantomPDF version 10.1.4 or later.