CVE-2021-38573: Critical severity Foxitsoftware Foxit Reader vulnerability
Published Aug 11, 2021
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
Affected Software
2 affected components
Foxitsoftware Foxit Reader<10.1.4
Foxitsoftware Phantompdf<10.1.4
Event History
Aug 11, 2021
CVE Published
via MITRE·09:12 PM
Data Sourced
via MITRE·09:12 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID for this issue is CVE-2021-38573.
2
What is the severity of CVE-2021-38573?
CVE-2021-38573 has a severity rating of 9.8, which is considered critical.
3
Which software versions are affected by CVE-2021-38573?
Foxit Reader and PhantomPDF versions up to 10.1.4 are affected by CVE-2021-38573.
4
What is the impact of CVE-2021-38573?
CVE-2021-38573 allows writing to arbitrary files, posing a risk of unauthorized data modification or destruction.
5
Is there a fix available for CVE-2021-38573?
Yes, updating Foxit Reader and PhantomPDF to version 10.1.4 or later will fix the vulnerability.