Description
Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in the context of the user who opens the file.
Problem types
CWE-121 Stack-based Buffer Overflow
Product status
* before 4.2.0.0928
Credits
dookie
References
www.exploit-db.com/exploits/15532
www.exploit-db.com/exploits/16621
raw.githubusercontent.com/...s/fileformat/foxit_title_bof.rb
www.exploit-db.com/exploits/15514/
www.foxit.com/pdf-reader/version-history.html
www.vulncheck.com/...-pdf-reader-title-stack-buffer-overflow