CVE-2018-17689
published 2019-01-24CVE-2018-17689: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required…
PriorityP352high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
3.85%
88.9th percentile
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the fillColor property of a radio button. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7070.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | phantompdf | — | — |
| foxitsoftware | phantompdf | <= 9.2.0.9297 | — |
| foxitsoftware | reader | <= 9.2.0.9297 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-77jp-q6gp-r976: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9
ghsa_unreviewed·2022-05-13
CVE-2018-17689 [HIGH] CWE-416 GHSA-77jp-q6gp-r976: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the fillColor property of a radio button. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7070.
Red Hat
S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
vendor_redhat·2018-05-14·CVSS 5.9
CVE-2017-17689 [MEDIUM] CWE-200 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Statement: The research paper talks about use of HTML as a back channel to create an oracle for modified encrypted emails. HTML emails which use external links like "" can cause security issues if they are honored by the MUAs. Due to flaws in MIME parsers many MUAs seem to concatenate decrypted HTML mine parts which makes it easy to plan such snippets in HTML emails. Please refer to https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060315.html about how GnuPG can mitigate this flaw.
For Thunderbird, this vulnerability was known as CVE-2018-5162 and reso
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-01-24
Published