PDFex attacks can exfiltrate content from encrypted PDF documents

Researchers from Ruhr University Bochum and Münster University of Applied Sciences have devised new attacks allowing them (and potential attackers) to recover the plaintext content of encrypted PDF documents. The attacks work against 27 widely-used des… Continue reading PDFex attacks can exfiltrate content from encrypted PDF documents

PDF viewers, online validation services vulnerable to digital signature spoofing attacks

Academics from Ruhr University Bochum have proven that the majority of popular PDF viewer apps and online digital signature validation services can be tricked into validating invalid signatures or validating signatures on documents that have been modif… Continue reading PDF viewers, online validation services vulnerable to digital signature spoofing attacks

Foxit PDF Reader Fixes High-Severity Remote Code Execution Flaws

Foxit Software has patched over 100 vulnerabilities in its popular Foxit PDF Reader. Many of the bugs tackled by the company include a wide array of high severity remote code execution vulnerabilities. Foxit on Friday released fixes for Foxit Reader 9…. Continue reading Foxit PDF Reader Fixes High-Severity Remote Code Execution Flaws

Cisco Talos discloses serious vulnerabilities in Foxit PDF Reader

Cisco Talos researcher Aleksandar Nikolic has unearthed one of the critical vulnerabilities fixed in the latest Adobe Acrobat and Reader security updates. He is also the one that recently discovered 23 vulnerabilities in another popular PDF reader: Fox… Continue reading Cisco Talos discloses serious vulnerabilities in Foxit PDF Reader

Two Foxit Reader RCE zero-day vulnerabilities disclosed

Trend Micro’s Zero Day Initiative has released details about two remote code execution zero-day flaws affecting popular freemium PDF tool Foxit Reader. The first one (CVE-2017-10951) is a command injection flaw that exists within the app.launchURL method, and arises because the method accepts more than just URLs as arguments. It does not filter file extensions, and therefore can be nade to launch executables. It was discovered by Ariele Caltabiano. The second one (CVE-2017-10952) is a … More Continue reading Two Foxit Reader RCE zero-day vulnerabilities disclosed