Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted remerge call.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/85379 | vdb entry |
https://www.foxitsoftware.com/support/security-bulletins.php | vendor advisory |
http://www.zerodayinitiative.com/advisories/ZDI-16-215 | third party advisory vdb entry |