Foxit PDF Reader Vulnerable to High-Severity Flaws

Discussion in 'other security issues & news' started by guest, Sep 30, 2019.

  1. guest

    guest Guest

    Vulnerability Spotlight: Foxit PDF Reader JavaScript Array.includes remote code execution vulnerability
    September 30, 2019
    https://blog.talosintelligence.com/2019/09/vuln-spotlight-foxit-PDF-JavaScript-sept-2019.html
     
  2. guest

    guest Guest

    Foxit PDF Reader Vulnerable to 8 High-Severity Flaws
    Eight high-severity vulnerabilities exist in the Foxit Reader tool for editing PDF files
    October 3, 2019

    https://threatpost.com/foxit-pdf-reader-vulnerable-to-8-high-severity-flaws/148897/
     
  3. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,943
    Location:
    USA
    Appreciate the heads up, mood. :thumb:
     
  4. guest

    guest Guest

  5. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    Perhaps someone knows, Is Portable apps still posting updates for Foxit Reader? This past few weeks I visited a few times the page for Foxit at PA to see if an update was available, but is not happening.

    The latest version they posted is from April. I think I might of read somewhere months ago that PA is not updating Foxit anymore but I cant remember if I really read that.

    https://portableapps.com/apps/office/foxit_reader_portable

    Bo
     
  6. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    97,992
    Location:
    U.S.A.
    Bo, Foxit Reader 9.7.0.29455 is listed in the Work In Progress queue. As to when it will get posted is anyone's guess:

    https://portableapps.com/development/outdated
     
  7. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    Thanks JR, appreciate the reply. Sometimes I go long whiles before updating Foxit, that's normal for me, but right now its probably a time were the update is really needed, this is specially so for people not running Foxit portable under Sandboxie's protection.

    Bo
     
  8. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    97,992
    Location:
    U.S.A.
    Bo, you're welcome. Unfortunately, ever since the below message appeared last year in the Outdated page, PortableApps software updates have been taking a lot longer than in the past. Perhaps the health issue is still ongoing. Take care.
     
  9. Beyonder

    Beyonder Registered Member

    Joined:
    Aug 26, 2011
    Posts:
    545
    This is why I go with SumatraPDF. All it's missing that I could ever want is the highlighting of text.
     
  10. klarm

    klarm Registered Member

    Joined:
    Apr 7, 2012
    Posts:
    85
    Location:
    europe
    I was just in search of a good PDF reader for win10.
    my candidates after some small research online were foxit and expert pdf reader by visagesoft.
    which one to pick now?
    this sumatraPDF mentioned above, proven safe?
    thanks
     
  11. zapjb

    zapjb Registered Member

    Joined:
    Nov 15, 2005
    Posts:
    5,556
    Location:
    USA still the best. But barely.
    I use PDF-XChange PDF Viewer.

    Used FixIt LONG time ago & it was having some weird problems that were corrected. Done. The problems were spying or some bs by FoxIt.

    Used & liked Sumatra.

    Every once in a while I need a feature that Sumatra didn't have. So I stick with PDF-XChange PDF Viewer.


    For print to PDF I use Doro PDF Writer.
    For PDF conversion I use Renee PDF aide.
     
  12. klarm

    klarm Registered Member

    Joined:
    Apr 7, 2012
    Posts:
    85
    Location:
    europe
    Thanks for info.
    Is it a need to have a PDF print program also cos if I'm not mistaken w10 has a built-in PDF print?
     
  13. guest

    guest Guest

    Canadian Centre for Cyber Security
    Foxit Reader and Foxit PhantomPDF Security Advisory

    Number: AV19-246
    October 29, 2019

    https://cyber.gc.ca/en/alerts/foxit-reader-and-foxit-phantompdf-security-advisory
     
  14. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    The updated version of Foxit portable is finally out. It took a long time but I am glad is out.

    https://portableapps.com/apps/office/foxit_reader_portable

    Bo
     
  15. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    97,992
    Location:
    U.S.A.
    Good to know; thanks! :thumb:
     
  16. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    You are welcome, JR. :)

    Bo
     
  17. guest

    guest Guest

    Foxit PDF Reader, PhantomPDF Open to Remote Code Execution
    April 20, 2020
    https://threatpost.com/foxit-pdf-reader-phantompdf-remote-code-execution/154942/
    Foxit: Security updates available in Foxit Reader 9.7.2 and Foxit PhantomPDF 9.7.2
     
  18. Reality

    Reality Registered Member

    Joined:
    Aug 25, 2013
    Posts:
    1,198
    Exactly my situation word for word - See no reason to change from PDF-XChange PDF Viewer
     
  19. guest

    guest Guest

    For Foxit's sake: Windows and Mac users alike urged to patch PhantomPDF over use-after-free vulns
    US CIST points spotlight at PDF reader 'n' creator suite
    October 13, 2020

    https://www.theregister.com/2020/10/13/foxit_phantompdf_vulns_update/
     
  20. guest

    guest Guest

    Foxit Plugs Multiple Security Holes in PDF Reader, Editor
    July 28, 2021
    https://www.securityweek.com/foxit-plugs-multiple-security-holes-pdf-reader-editor
    Cisco Talos: Vulnerability Spotlight: Use-after-free vulnerabilities in Foxit PDF Reader
     
  21. guest

    guest Guest

    Foxit Patches Several Code Execution Vulnerabilities in PDF Reader
    By Ionut Arghire - November 11, 2022
    Cisco Talos: Vulnerability Spotlight: Use-after-free vulnerabilities in Foxit Reader could lead to arbitrary code execution
     
  22. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    I always disable JavaScript in my PDF readers.
     
  23. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes I do the same, this should reduce the attack surface.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.