CVE-2024-9253
published 2024-11-22CVE-2024-9253: Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information…
PriorityP431high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.42%
34.7th percentile
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of AcroForms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-24492.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | <= 11.2.10.53951 | — |
| foxit | pdf_editor | 12.0 – 12.1.7.15526 | — |
| foxit | pdf_editor | 13.0 – 13.1.3.22478 | — |
| foxit | pdf_editor | 2023.0 – 2023.3.0.23028 | — |
| foxit | pdf_editor | 2024.0 – 2024.2.3.25184 | — |
| foxit | pdf_reader | <= 2024.2.3.25184 | — |
| foxit | pdf_reader | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjmj-84v8-m369: Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
ghsa_unreviewed·2024-11-23
CVE-2024-9253 [LOW] CWE-125 GHSA-vjmj-84v8-m369: Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of AcroForms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-24492.
GHSA
com.enonic.xp:lib-auth vulnerable to Session Fixation
ghsa·2022-10-12
CVE-2024-23679 [CRITICAL] CWE-384 com.enonic.xp:lib-auth vulnerable to Session Fixation
com.enonic.xp:lib-auth vulnerable to Session Fixation
### Impact
All id-providers using lib-auth `login` method.
### Patches
https://github.com/enonic/xp/commit/0189975691e9e6407a9fee87006f730e84f734ff
https://github.com/enonic/xp/commit/2abac31cec8679074debc4f1fb69c25930e40842
https://github.com/enonic/xp/commit/1f44674eb9ab3fbab7103e8d08067846e88bace4
### Workarounds
Don't use lib-auth for `login`.
Java API uses low-level structures and allows to invalidate previous session before auth-info is added.
### References
https://github.com/enonic/xp/issues/9253
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-22
Published