CVE-2022-24954: Buffer Overflow
Published Feb 11, 2022
·Updated
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.
Affected Software
4 affected components
Foxit PDF Reader<=11.1.0.52543
Microsoft Windows
Foxit PDF Editor<=10.1.6.37749
Foxit PDF Editor>=11.0.1.0719<=11.2.0.53415
Remediation
Patch Available
Event History
Feb 11, 2022
CVE Published
via MITRE·01:40 AM
Data Sourced
via MITRE·01:40 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-24954?
CVE-2022-24954 has a medium severity rating due to its potential for exploitation through a stack-based buffer overflow.
2
How do I fix CVE-2022-24954?
To fix CVE-2022-24954, users should update Foxit PDF Reader and Foxit PDF Editor to version 11.2.1 or later.
3
What software is affected by CVE-2022-24954?
CVE-2022-24954 affects Foxit PDF Reader versions prior to 11.2.1 and Foxit PDF Editor versions prior to 11.2.1.
4
What type of vulnerability is CVE-2022-24954?
CVE-2022-24954 is classified as a stack-based buffer overflow vulnerability.
5
Can CVE-2022-24954 be exploited remotely?
Yes, CVE-2022-24954 can potentially be exploited remotely if a user opens a specially crafted PDF document.