Current Foxit Reader can execute malicious code

Discussion in 'other security issues & news' started by ronjor, Jan 10, 2013.

Thread Status:
Not open for further replies.
  1. safeguy

    safeguy Registered Member

    Joined:
    Jun 14, 2010
    Posts:
    1,795
    SumatraPDf lacks sandboxing so that's 1 weak point. If you really want/need to, you can force it to use Low IL though.

    http://blog.didierstevens.com/2010/10/11/pdf-dep-aslr-and-integrity-levels/

    On the other hand, it doesn't support JavaScript and that itself renders most PDF exploits moot currently. It also has much less code compared to Adobe or Foxit.

    Then there's also this:
    http://blog.didierstevens.com/2010/03/29/escape-from-pdf/
     
  2. Now I respect Didier Steven's so that exploit is all the more reason not to use PDF's.
     
  3. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,596
    Location:
    Texas
    http://www.infoworld.com/d/security...rability-in-pdf-viewer-browser-plug-in-211038
     
  4. mick92z

    mick92z Registered Member

    Joined:
    Apr 27, 2007
    Posts:
    548
    Location:
    Nottingham
    Nice one :thumb: Just installed it. Getting sick of Foxit, problems uninstalling, toolbar offers etc. Cheers
    One thing i don't understand. I installed Sumatra on a laptop using default settings ( no plug in ) All was fine,. On my desktop, it would not read web pdf's, had to re-install and choose the plug in. How can that be
     
    Last edited: Jan 18, 2013
  5. TheKid7

    TheKid7 Registered Member

    Joined:
    Jul 22, 2006
    Posts:
    3,576
    Fixed Foxit Reader released:
    http://www.h-online.com/security/news/item/Fixed-Foxit-Reader-released-1787736.html
     
  6. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,564
    Location:
    New York City
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.