Impact
The vulnerability arises when Foxit PDF Editor or Reader processes a PDF that contains an abnormal color space whose attributes reference a semantically malformed function. The application does not validate the function’s output; when the value is later read the parser creates an illegal pointer that accesses memory outside the valid bounds, causing the program to crash. This out‑of‑bounds read (CWE‑125) results in a denial‑of‑service failure, terminating the PDF viewer without compromising the underlying system or leaking sensitive data.
Affected Systems
The flaw affects Foxit Software Inc.’s PDF products, namely Foxit PDF Editor and Foxit PDF Reader. The advisory does not provide a specific affected version range, implying that any build released without the patch could be vulnerable.
Risk and Exploitability
With a CVSS score of 6.1, the issue is classified as moderate; the EPSS score of < 1% indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is that an attacker crafts a malicious PDF and entices a user to open it. Successful exploitation leads to a crash, impacting service availability but not granting elevation of privilege or data leakage. The overall risk therefore depends on the frequency of exposure to malicious PDFs and the importance of the PDF viewer in the organization’s workflows.
OpenCVE Enrichment