Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
基于Windows的Foxit Reader和PhantomPDF数据伪造问题漏洞
Vulnerability Description
Foxit Reader和Foxit PhantomPDF for Windows都是中国福昕(Foxit)公司的产品。Foxit Reader是一款PDF文档阅读器。Foxit PhantomPDF for Windows是一款基于Windows平台的PDF文档阅读器。 基于Windows平台的Foxit Reader 9.3.0.10826及之前版本和PhantomPDF 9.3.0.10826及之前版本中存在安全漏洞。攻击者可借助PDF文件利用该漏洞绕过签名验证并提供不正确的检测结果。
CVSS Information
N/A
Vulnerability Type
N/A