CVE-2021-38569: High severity Foxitsoftware Foxit Reader vulnerability
Published Aug 11, 2021
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.
Affected Software
2 affected components
Foxitsoftware Foxit Reader<10.1.4
Foxitsoftware Phantompdf<10.1.4
Event History
Aug 11, 2021
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-38569?
CVE-2021-38569 is a vulnerability discovered in Foxit Reader and PhantomPDF before version 10.1.4 that allows stack consumption via recursive function calls during the handling of XFA forms or link objects.
2
What software versions are affected by CVE-2021-38569?
Foxit Reader and PhantomPDF versions up to and excluding 10.1.4 are affected by CVE-2021-38569.
3
How severe is CVE-2021-38569?
CVE-2021-38569 has a severity rating of 7.5 (high).
4
How can I fix CVE-2021-38569?
To fix CVE-2021-38569, you should update Foxit Reader and PhantomPDF to version 10.1.4 or later.
5
Where can I find more information about CVE-2021-38569?
You can find more information about CVE-2021-38569 in the security bulletins section of the Foxit Software support website.