Foxit PDFÔĶÁÆ÷¶à¸öÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-10-08Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5031£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-13326£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º7.8
CVE±àºÅ£ºCVE-2019-13327£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º7.8
CVE±àºÅ£ºCVE-2019-13328£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º7.8
CVE±àºÅ£ºCVE-2019-13329£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º7.8
CVE±àºÅ£ºCVE-2019-13330£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º7.8
CVE±àºÅ£ºCVE-2019-13331£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º7.8
CVE±àºÅ£ºCVE-2019-13332£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º7.8
Ó°Ïì°æ±¾
»ùÓÚWindowsƽ̨µÄFoxit Reader 9.6.0.25114¼°Ö®Ç°°æ±¾ÖеÄV8ÒýÇæ
Îó²î¸ÅÊö
FoxitÈí¼þÐû²¼Á˹ØÓÚFoxit pdfÔĶÁÆ÷µÄ8¸öÎó²îʹÓᣡ£¡£¡£¡£FoxitÈí¼þÈ¥ÄêµÄÊý¾ÝÏÔʾ²úƷʹÓÃÓû§Áè¼Ý4.75ÒÚ¡£¡£¡£¡£¡£ÕâЩÎó²î¾ù¿ÉÔÊÐíºÚ¿ÍÔÚ¸ÃÈí¼þÖÐÔ¶³ÌÖ´ÐдúÂ룬£¬µ«ÐèÒªÊܺ¦ÕßÊÂÏÈ»á¼û¶ñÒâÍøÕ¾»ò·¿ª¶ñÒâÎļþ¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±ÔÚFoxit PDFÔĶÁÆ÷µÄJavaScriptÒýÇæµÄJavaScript Array.includesÖз¢Ã÷ÁËÒ»¸öÄÚ´æÆÆËðÎó²îCVE-2019-5031¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÒ»¸öÈ«ÐÄαÔìµÄPDFÎĵµ¾Í¿ÉÒÔ´¥·¢Ò»¸öout-of-memoryÌõ¼þ£¬£¬µ¼Ö´¦Öóͷ£²»µ±Òý·¢í§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¹¥»÷ÕßÖ»ÐèÒªÓÕʹÓû§·¿ª¶ñÒâpdfÎļþ¾Í¿ÉÒÔ´¥·¢¸ÃÎó²î¡£¡£¡£¡£¡£ÈôÊÇÆôÓÃÁ˶ÔÓ¦µÄä¯ÀÀÆ÷²å¼þÀ©Õ¹£¬£¬»á¼û¶ñÒâÕ¾µãÒ²»á´¥·¢¸ÃÎó²î¡£¡£¡£¡£¡£
ÆäËû7¸öÎó²îµÄCVSS·ÖÖµ¶¼Îª7.8·Ö¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÕâЩÎó²î¿ÉÒÔÔ¶³Ì»ñÈ¡Êܺ¦ÕßϵͳµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£
CVE-2019-13326£¬£¬CVE-2019-13327£¬£¬CVE-2019-13328Õâ3¸öÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÓëFoxit Reader´¦Öóͷ£AcroFormÓòµÄ·½·¨Óйأ¬£¬ÔÚº¬ÓÐformÓòµÄpdfÎļþÖпÉÒÔÊäÈëÄÚÈÝ¡£¡£¡£¡£¡£ÓÉÓÚÔÚ¹¤¾ßÉÏÖ´ÐвÙ×÷ǰûÓÐÑéÖ¤¹¤¾ß±£´æµÄÓÐÓÃÐÔ£¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔÚÄ¿½ñÀú³ÌÇéÐÎÏÂÖ´ÐдúÂë¡£¡£¡£¡£¡£
CVE-2019-13329Îó²îÊÇ´¦Öóͷ£TIFÎļþʱÒý·¢µÄÎÊÌ⣬£¬CVE-2019-13330£¬£¬CVE-2019-13331ÊÇ´¦Öóͷ£JPGÎļþʱÒý·¢µÄÎó²î£¬£¬CVE-2019-13332ÊÇ´¦Öóͷ£XFA FormÄ£°åʱÒý·¢µÄÎó²î¡£¡£¡£¡£¡£XFAÌåÏÖXML Form Architecture£¬£¬ÊÇJetFormÓÃÀ´ÔöÇ¿web form´¦Öóͷ£µÄרÓÃXML¹æ¸ñ˵Ã÷¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://www.foxitsoftware.com/support/security-bulletins.php
²Î¿¼Á´½Ó
https://threatpost.com/foxit-pdf-reader-vulnerable-to-8-high-severity-flaws/148897/


¾©¹«Íø°²±¸11010802024551ºÅ