CVE Vulnerabilities

CVE-2021-38572

Published: Aug 11, 2021 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.

Affected Software

Name Vendor Start Version End Version
Foxit_reader Foxitsoftware * 10.1.4 (excluding)
Phantompdf Foxitsoftware * 10.1.4 (excluding)

References