Foxit PDFÔĶÁÆ÷¶à¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-08

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5031£¬ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬ £¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-13326£¬ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.8

CVE±àºÅ£ºCVE-2019-13327£¬ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.8

CVE±àºÅ£ºCVE-2019-13328£¬ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.8

CVE±àºÅ£ºCVE-2019-13329£¬ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.8

CVE±àºÅ£ºCVE-2019-13330£¬ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.8

CVE±àºÅ£ºCVE-2019-13331£¬ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.8

CVE±àºÅ£ºCVE-2019-13332£¬ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.8


Ó°Ïì°æ±¾


»ùÓÚWindowsƽ̨µÄFoxit Reader 9.6.0.25114¼°Ö®Ç°°æ±¾ÖеÄV8ÒýÇæ


Îó²î¸ÅÊö


FoxitÈí¼þÐû²¼Á˹ØÓÚFoxit pdfÔĶÁÆ÷µÄ8¸öÎó²îʹÓᣡ£¡£¡£¡£¡£¡£¡£FoxitÈí¼þÈ¥ÄêµÄÊý¾ÝÏÔʾ²úƷʹÓÃÓû§Áè¼Ý4.75ÒÚ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¾ù¿ÉÔÊÐíºÚ¿ÍÔÚ¸ÃÈí¼þÖÐÔ¶³ÌÖ´ÐдúÂ룬 £¬£¬£¬£¬£¬£¬£¬µ«ÐèÒªÊܺ¦ÕßÊÂÏÈ»á¼û¶ñÒâÍøÕ¾»ò·­¿ª¶ñÒâÎļþ¡£¡£¡£¡£¡£¡£¡£¡£


Ñо¿Ö°Ô±ÔÚFoxit PDFÔĶÁÆ÷µÄJavaScriptÒýÇæµÄJavaScript Array.includesÖз¢Ã÷ÁËÒ»¸öÄÚ´æÆÆËðÎó²îCVE-2019-5031¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÒ»¸öÈ«ÐÄαÔìµÄPDFÎĵµ¾Í¿ÉÒÔ´¥·¢Ò»¸öout-of-memoryÌõ¼þ£¬ £¬£¬£¬£¬£¬£¬£¬µ¼Ö´¦Öóͷ£²»µ±Òý·¢í§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ»ÐèÒªÓÕʹÓû§·­¿ª¶ñÒâpdfÎļþ¾Í¿ÉÒÔ´¥·¢¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÆôÓÃÁ˶ÔÓ¦µÄä¯ÀÀÆ÷²å¼þÀ©Õ¹£¬ £¬£¬£¬£¬£¬£¬£¬»á¼û¶ñÒâÕ¾µãÒ²»á´¥·¢¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£¡£


ÆäËû7¸öÎó²îµÄCVSS·ÖÖµ¶¼Îª7.8·Ö¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÕâЩÎó²î¿ÉÒÔÔ¶³Ì»ñÈ¡Êܺ¦ÕßϵͳµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-13326£¬ £¬£¬£¬£¬£¬£¬£¬CVE-2019-13327£¬ £¬£¬£¬£¬£¬£¬£¬CVE-2019-13328Õâ3¸öÎó²î±¬·¢µÄÔµ¹ÊÔ­ÓÉÓëFoxit Reader´¦Öóͷ£AcroFormÓòµÄ·½·¨ÓйØ£¬ £¬£¬£¬£¬£¬£¬£¬ÔÚº¬ÓÐformÓòµÄpdfÎļþÖпÉÒÔÊäÈëÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÔÚ¹¤¾ßÉÏÖ´ÐвÙ×÷ǰûÓÐÑéÖ¤¹¤¾ß±£´æµÄÓÐÓÃÐÔ£¬ £¬£¬£¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔÚÄ¿½ñÀú³ÌÇéÐÎÏÂÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-13329Îó²îÊÇ´¦Öóͷ£TIFÎļþʱÒý·¢µÄÎÊÌ⣬ £¬£¬£¬£¬£¬£¬£¬CVE-2019-13330£¬ £¬£¬£¬£¬£¬£¬£¬CVE-2019-13331ÊÇ´¦Öóͷ£JPGÎļþʱÒý·¢µÄÎó²î£¬ £¬£¬£¬£¬£¬£¬£¬CVE-2019-13332ÊÇ´¦Öóͷ£XFA FormÄ£°åʱÒý·¢µÄÎó²î¡£¡£¡£¡£¡£¡£¡£¡£XFAÌåÏÖXML Form Architecture£¬ £¬£¬£¬£¬£¬£¬£¬ÊÇJetFormÓÃÀ´ÔöÇ¿web form´¦Öóͷ£µÄרÓÃXML¹æ¸ñ˵Ã÷¡£¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬ £¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://www.foxitsoftware.com/support/security-bulletins.php


²Î¿¼Á´½Ó


https://threatpost.com/foxit-pdf-reader-vulnerable-to-8-high-severity-flaws/148897/