An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.
2020-10-02T08:15:12.807
2024-11-21T05:20:02.400
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | foxitsoftware | foxit_reader | < 4.1 | Yes |
Application | foxitsoftware | phantompdf | < 4.1 | Yes |
Operating System | apple | macos | - | No |