Skip to content


Foxit Reader Firefox Plugin Big Security Vulnerability

OK, now this is BIG. Everyone’s favorite Adobe’s Acrobat Reader substitute, Foxit Reader, mind you, has an enormous hole. It is a security flaw, not yet patched, that does the basic: allows someone to take control of your machine remotely. I myself found this exploit, while doing an update and installing the firefox plugin. Then, my Avira Antivir detected a trojan. At first, tought that it was a false positive, but turned out to be a real threat. It may allow hackers to harvest passwords and bank/credit cards data. The complete explanation of that exploit:

Foxit Reader Firefox Plugin Memory Corruption Vulnerability
Secunia Advisory: SA37049 – Highly critical

Description:
A vulnerability has been discovered in Foxit Reader, which can be exploited by malicious people to potentially compromise a user’s system.

The vulnerability is caused due to an error in the Foxit Reader plugin for Firefox (npFoxitReaderPlugin.dll). This can be exploited to trigger a memory corruption by tricking a user into visiting a specially crafted web page which repeatedly loads and unloads the plugin.

Successful exploitation may allow execution of arbitrary code.

This is related to vulnerability #12 in: SA36983

The vulnerability is confirmed with Foxit Reader version 3.1.2.1013 and Mozilla Firefox 3.5.3. Other versions may also be affected.

Solution:
Do not visit untrusted websites or follow untrusted links.Disable the Foxit Reader plugin in Firefox.

Provided and/or discovered by:
Originally discovered in Adobe Reader by SkyLined.
Reported in Foxit Reader by MrX.

http://secunia.com/advisories/37049/

This affects the latest version update of Foxit Reader – Firefox Plugin
The source is the trusted Secunia website. So, I recommend that you do one of the following: don’t install the firefox plugin; use another pdf reader, like the PDF X-CHANGE VIEWER.

Hope it is usefull, and until the next!

Posted in Security.

Tagged with , , .


3 Responses

Stay in touch with the conversation, subscribe to the RSS feed for comments on this post.

  1. belkevich8 says

    I want to quote your post in my blog. It can?
    And you et an account on Twitter?

    • reverendo says

      Sure! Feel free to quote any of the contents of my blog. Sorry for the wait.

Continuing the Discussion

  1. The Web Harvest Tutorials. | 7Wins.eu linked to this post on December 6, 2009

    [...] Tutorial: Create A Retro Cosmic Design in Photoshop | fudgegraphics | for loversWebsurf Recorder » Web Development on Windows using Apache + MySQL + PHP TutorialExpertaya » HtmlUnit as Java Screen Scraping Library PSHERO | Photoshop Tutorials | Transformers Effect Artistic Web Site Banner « WS 320 Gender & TechnologyXNAtutorial.com » Weekly Update – SpaceWar CompetitionFoxit Reader Firefox Plugin Big Security Vulnerability – Tutorial for All – Do Yourself [...]



Some HTML is OK

or, reply to this post via trackback.