First published: Wed Aug 11 2021(Updated: )
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Foxit Reader | <10.1.4 | |
Foxitsoftware Phantompdf | <10.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38572 is critical with a CVSS score of 9.8.
Foxit Reader and PhantomPDF versions up to 10.1.4 are affected by CVE-2021-38572.
CVE-2021-38572 allows writing to arbitrary files because the extractPages pathname is not validated in Foxit Reader and PhantomPDF.
To fix CVE-2021-38572, update Foxit Reader and PhantomPDF to version 10.1.4 or later.
You can find more information about CVE-2021-38572 on the Foxit Software's security bulletins page.