Heap-based Buffer Overflow Remote Code Execution Vulnerability in Foxit PDF Reader
CVE-2021-34971
Summary
A vulnerability exists within Foxit PDF Reader that allows remote attackers to execute arbitrary code by exploiting a parsing error in JPG2000 files. The flaw stems from inadequate validation of user-supplied data length prior to buffer allocation in heap memory. As a consequence, when a targeted user opens a maliciously crafted JPG2000 file or navigates to an unsafe web page, an attacker can gain unauthorized access and execute code within the context of the affected application. This vulnerability highlights the critical importance of robust input validation and secure coding practices. For detailed information, consult the vendor's advisory and relevant security bulletins.
Affected Version(s)
PDF Reader 11.0.1.49938
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved