Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://www.foxit.com/support/security-bulletins.html | vendor advisory |
https://drive.google.com/file/d/1WpwDgVRU-Mb792z6dgDoWMXDRSeB8ZLU/view?usp=sharing | third party advisory exploit |