Foxit Reader < 8.0.2 Multiple Vulnerabilities

High Nessus Network Monitor Plugin ID 9491

Synopsis

The remote host has been observed running a version of Foxit Reader that is subject to multiple attack vectors.

Description

Versions of Foxit Reader prior to 8.0.2 are affected by the following vulnerbilities :

- An out-of-bounds access flaw is triggered during the handling of 'JPXDecode' streams. This may allow a context-dependent attacker to disclose memory or potentially execute arbitrary code. (OSVDB 142700)
- A flaw is triggered as certain input is not properly validated. This may allow a context-dependent attacker to corrupt memory and potentially execute arbitrary code. (OSVDB 142701)
- An out-of-bounds read flaw exists in the 'ConvertToPDF' plugin that is triggered during the handling of a specially crafted BMP image. This may allow a context-dependent attacker to disclose memory. (OSVDB 142702)
- An unspecified DLL hijacking flaw may allow a context-dependent attacker to potentially execute arbitrary code. No further details have been provided. (OSVDB 142703)
- A flaw is triggered as certain input is not properly validated when handling JPEG2000 images. This may allow a context-dependent attacker to corrupt memory and potentially execute arbitrary code. (OSVDB 142704)
- An out-of-bounds access flaw is triggered during the handling of a specially crafted JPEG2000 image. This may allow a context-dependent attacker to disclose memory or potentially execute arbitrary code. (OSVDB 142705)
- An out-of-bounds access flaw in the 'ConvertToPDF' plugin is triggered during the handling of a specially crafted TIFF image. This may allow a context-dependent attacker to disclose memory or potentially execute arbitrary code. (OSVDB 142706)
- A use-after-free error is triggered when handling 'FlateDecode' streams. This may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. (OSVDB 142707)

Solution

Upgrade Foxit Reader to version 8.0.2 or later.

See Also

https://www.foxitsoftware.com/support/security-bulletins.php

Plugin Details

Severity: High

ID: 9491

File Name: 9491.prm

Family: CGI

Published: 2016/09/02

Modified: 2016/10/26

Dependencies: 9456

Risk Information

Risk Factor: High

CVSSv2

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

CVSSv3

Base Score: 8.1

Temporal Score: 7.7

Vector: CVSS3#AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS3#E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:foxitsoftware:reader

Patch Publication Date: 2016/08/08

Vulnerability Publication Date: 2016/08/08

Reference Information

CVE: CVE-2016-6230, CVE-2016-6476, CVE-2016-6477, CVE-2016-6478, CVE-2016-6860, CVE-2016-6867, CVE-2016-6868