Foxit Reader... CVE-2017-10951,CVE-2017-10952

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### A tale about Foxit Reader - Safe Reading mode and other vulnerabilities Some days ago someone send me the following link, which describes two vulnerabilities in Foxit Reader: http://thehackernews.com/2017/08/two-critical-zero-day-flaws-disclosed.html These two vulnerabilities are similar to the behavior of Foxit Reader I presented at Appsec Belfast 2017. Unfortunately the recording was never published, so I decided it's time for a blog post to give some additional information about these vulnerabilities. First I have to describe the implemented security model in Foxit Reader. #### Safe-Reading mode Foxit Reader implements a one-line defense, the so-called "Safe-Reading mode". It is enabled by default. In case it is enabled it prohibits the execution of scripts and other features, which can harm the security of the end user. During my presentation I said, that this feature should never ever be disabled. In case a vulnerability requires a disabled "Safe-Reading mode", Foxit will...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息