First published: Fri Feb 11 2022(Updated: )
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader | <=11.1.0.52543 | |
Microsoft Windows | ||
Foxit PDF Editor for Mac | <=10.1.6.37749 | |
Foxit PDF Editor for Mac | >=11.0.1.0719<=11.2.0.53415 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24954 has a medium severity rating due to its potential for exploitation through a stack-based buffer overflow.
To fix CVE-2022-24954, users should update Foxit PDF Reader and Foxit PDF Editor to version 11.2.1 or later.
CVE-2022-24954 affects Foxit PDF Reader versions prior to 11.2.1 and Foxit PDF Editor versions prior to 11.2.1.
CVE-2022-24954 is classified as a stack-based buffer overflow vulnerability.
Yes, CVE-2022-24954 can potentially be exploited remotely if a user opens a specially crafted PDF document.