Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer and DataView objects is mishandled.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.foxitsoftware.com/support/security-bulletins.php | patch vendor advisory |
http://www.securitytracker.com/id/1041769 | vdb entry third party advisory |