SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#570177

Foxit Reader vulnerable to arbitrary command execution

Overview

Foxit Reader contains a vulnerability that may allow an attacker to execute arbitrary commands without requiring user interaction.

I. Description

Foxit Reader is software designed to view Portable Document Format (PDF) files. The Adobe PDF Reference supports a "Launch action" that "... launches an application or opens or prints a document." Foxit Reader uses the ShellExecute function to handle PDFs that use a Launch action. In some cases, Foxit Reader will not prompt the user before an application is launched with a Launch action. It is also reported that the Launch Action can be used to launch an executable that is included in the PDF document, which results in arbitrary code execution.

II. Impact

By convincing a user to open a PDF document, e.g. by visiting a website, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system.

III. Solution

Apply an update

This issue is addressed in Foxit Reader 3.2.1.0401. This update will cause Foxit Reader to prompt the user before using a Launch Action.

Systems Affected

VendorStatusDate NotifiedDate Updated
Foxit Software CompanyVulnerable2010-03-302010-04-02

References

http://blog.didierstevens.com/2010/03/29/escape-from-pdf/
http://blog.didierstevens.com/2010/03/31/escape-from-foxit-reader/
http://www.adobe.com/devnet/acrobat/pdfs/pdf_reference_1-7.pdf
http://www.f-secure.com/weblog/archives/00001923.html
http://msdn.microsoft.com/en-us/library/bb762153%28VS.85%29.aspx

Credit

This vulnerability was reported by Didier Stevens.

This document was written by Will Dormann.

Other Information

Date Public:2010-03-31
Date First Published:2010-04-02
Date Last Updated:2010-04-15
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Severity Metric:33.17
Document Revision:6

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2010 by US-CERT, a government organization
Disclaimers and copyright information
Get a PDF Reader