ZDI-CAN-7131: Foxit PhantomPDF HTML2PDF HTML Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Array.prototype.concat. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-7131?
The severity of ZDI-CAN-7131 is classified as critical due to the potential for remote arbitrary code execution.
How do I fix ZDI-CAN-7131?
To fix ZDI-CAN-7131, ensure you are using the latest version of Foxit PhantomPDF and apply any available security updates.
What types of attacks can exploit ZDI-CAN-7131?
ZDI-CAN-7131 can be exploited through remote code execution by tricking users into visiting malicious web pages or opening malicious files.
Is user interaction required to exploit ZDI-CAN-7131?
Yes, user interaction is required for ZDI-CAN-7131, as the victim must visit a malicious page or open a crafted file.
Which versions of Foxit PhantomPDF are affected by ZDI-CAN-7131?
ZDI-CAN-7131 affects multiple versions of Foxit PhantomPDF for Windows; users should check specific release notes for details.