CVE-2026-57258: Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream
The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57258?
CVE-2026-57258 has a severity rating of medium, specifically a score of 6.1.
How does CVE-2026-57258 affect Foxit PDF Editor and Reader?
CVE-2026-57258 causes crashes in Foxit PDF Editor and Reader due to out-of-bounds reads from malformed PRC 3D streams.
Can I exploit CVE-2026-57258 without authentication?
Yes, CVE-2026-57258 can be exploited without authentication, as it does not require prior user interaction.
What is the impact of CVE-2026-57258 on data confidentiality?
CVE-2026-57258 has a low impact on data confidentiality, providing only limited information disclosure.
How can I mitigate the risks associated with CVE-2026-57258?
To mitigate the risks of CVE-2026-57258, users should update to the latest version of Foxit PDF Editor or Reader that addresses this vulnerability.