Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:CVE-2018-3956-INFO-DIS

Severity

Minor

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

Foxit Reader and PhantomPDF XFA xdpContent Information Disclosure

Release Date

2019/02/25

Update Number

3145

Supported Platforms

idp-4.1+, isg-3.5.141818+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Foxit Reader and PhantomPDF XFA xdpContent Information Disclosure


This signature detects attempts to exploit a known vulnerability Foxit Reader and PhantomPDF. Successful exploitation would allow the attacker to gain sensitive information.

Extended Description

An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

Affected Products

  • Foxitsoftware phantompdf 9.3.0.10826
  • Foxitsoftware reader 9.3.0.10826

References

  • CVE: CVE-2018-3956
  • URL: https://www.talosintelligence.com/vulnerability_reports/talos-2018-0626
  • URL: https://www.foxitsoftware.com/support/security-bulletins.php#content-2019

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out