First published: Wed Aug 11 2021(Updated: )
An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It mishandles situations in which an array size (derived from a /Size entry) is smaller than the maximum indirect object number, and thus there is an attempted incorrect array access (leading to a NULL pointer dereference, or out-of-bounds read or write).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit PDF Reader | <=11.0.0.0510 | |
Foxitsoftware Pdf Editor | <=11.0.0.0510 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38563 is a vulnerability discovered in Foxit PDF Reader and PDF Editor versions before 11.0.1 that mishandles situations where an array size is smaller than the maximum indirect object number, leading to a NULL pointer dereference.
CVE-2021-38563 affects versions of Foxit PDF Reader and PDF Editor before 11.0.1 by allowing an attempted incorrect array access, leading to a NULL pointer dereference.
CVE-2021-38563 has a severity rating of 9.8 (Critical).
To fix CVE-2021-38563, update your Foxit PDF Reader and PDF Editor to version 11.0.1 or later, which addresses the vulnerability.
More information about CVE-2021-38563 can be found on the Foxit Software security bulletins page at https://www.foxitsoftware.com/support/security-bulletins.php.