Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.foxit.com/support/security-bulletins.html | patch vendor advisory |
https://twitter.com/l33d0hyun/status/1487047927415459851 | third party advisory exploit |