HTTP: Foxit Reader and PhantomPDF XFA xdpContent Information Disclosure

This signature detects attempts to exploit a known vulnerability Foxit Reader and PhantomPDF. Successful exploitation would allow the attacker to gain sensitive information.

Extended Description

An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

Short Name
HTTP:CVE-2018-3956-INFO-DIS
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-3956 Disclosure Foxit Information PhantomPDF Reader XFA and xdpContent
Release Date
02/25/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3415
False Positive
Unknown
CVSS Score

5.8

Found a potential security threat?