CVE Vulnerabilities

CVE-2021-38572

Published: Aug 11, 2021 | Modified: Aug 12, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.

Affected Software

Name Vendor Start Version End Version
Foxit_reader Foxitsoftware * 10.1.4 (excluding)
Phantompdf Foxitsoftware * 10.1.4 (excluding)

References