CVE-2021-38572: Critical severity Foxitsoftware Foxit Reader vulnerability
Published Aug 11, 2021
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.
Affected Software
2 affected components
Foxitsoftware Foxit Reader<10.1.4
Foxitsoftware Phantompdf<10.1.4
Event History
Aug 11, 2021
CVE Published
via MITRE·09:13 PM
Data Sourced
via MITRE·09:13 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-38572?
The severity of CVE-2021-38572 is critical with a CVSS score of 9.8.
2
What software is affected by CVE-2021-38572?
Foxit Reader and PhantomPDF versions up to 10.1.4 are affected by CVE-2021-38572.
3
How does CVE-2021-38572 allow writing to arbitrary files?
CVE-2021-38572 allows writing to arbitrary files because the extractPages pathname is not validated in Foxit Reader and PhantomPDF.
4
What is the fix for CVE-2021-38572?
To fix CVE-2021-38572, update Foxit Reader and PhantomPDF to version 10.1.4 or later.
5
Where can I find more information about CVE-2021-38572?
You can find more information about CVE-2021-38572 on the Foxit Software's security bulletins page.