First published: Wed Aug 11 2021(Updated: )
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Foxit Reader | <10.1.4 | |
Foxitsoftware Phantompdf | <10.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-38573.
CVE-2021-38573 has a severity rating of 9.8, which is considered critical.
Foxit Reader and PhantomPDF versions up to 10.1.4 are affected by CVE-2021-38573.
CVE-2021-38573 allows writing to arbitrary files, posing a risk of unauthorized data modification or destruction.
Yes, updating Foxit Reader and PhantomPDF to version 10.1.4 or later will fix the vulnerability.