Foxit PDF Reader is well and truly foxed up, but vendor won't patch

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
We've got Safe Mode and that's safe enough, vendor tells ~400m users
The Zero Day Initiative (ZDI) has gone public with a Foxit PDF Reader vulnerability without a fix, because the vendor resisted patching.

The ZDI made the decision last week that the two vulns, CVE-2017-10951 and CVE-2017-10952, warranted release so at least some of Foxit's 400 million users could protect themselves.

In both cases, the only chance at mitigation is to use the software's "Secure Mode" when opening files, something that users might skip in normal circumstances.

CVE-2017-10951 allows the the app.launchURL method to execute a system call from a user-supplied string, with insufficient validation.

CVE-2017-10952 means the saveAs JavaScript function doesn't validate what the user supplies, letting an attacker write "arbitrary files into attacker controlled locations."

Both are restricted to execution with the user's rights.

No fix
ZDI went public after its usual 120-day cycle because the authors made it clear no fix was coming, with this response:

"Foxit Reader & PhantomPDF has a Safe Reading Mode which is enabled by default to control the running of JavaScript, which can effectively guard against potential vulnerabilities from unauthorized JavaScript actions."

Foxit Software appears to be content to suggest users run its wares in Safe Mode, as its security advisories home page offers that advice for bugs identified in 2011.

The company did patch a dirty dozen bugs in 2016. ®
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Boyyyyss... We are talking about a software that can display documents. So, why there are so many bugs?
If all Foxit did was display documents, like Sumatra, then there would not be so many bugs. But it does more, because some complex, business-oriented PDF docs contain scripts, for enhanced functionality, like interactive form filling, etc.
If you just want to view and print a regular PDF, use Sumatra. It's safe.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top