This application requires Javascript for optimal performance.

Foxit.PDF.Reader.Javascript.File.Write

Release Date

May 18, 2011

Severity

high

Impact

System compromise

Description

This indicates a possible attack against a file write vulnerabilitiy in Foxit PDF Reader, the cause of the vulnerability is related to the JavaScript API which allows createDataObject() to create or overwrite arbitrary files.

Affected Products

Foxit PDF Reader 4.3.1.0118 and earlier.

Recommended Actions

Please refer to vendor's website for update or patch:
http://www.foxitsoftware.com/pdf/reader/

Coverage

IPS
VCM

Reference/s

http://scarybeastsecurity.blogspot.com/2011/03/dangerous-file-write-bug-in-foxit-pdf.html
http://secunia.com/advisories/43776/

Reference: VID-26191