An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.
2020-12-31T21:15:12.253
2024-11-21T05:28:32.400
Modified
CVSSv3.1: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | foxitsoftware | foxit_reader | < 10.1.1 | Yes |
Application | foxitsoftware | phantompdf | < 9.7.5 | Yes |
Application | foxitsoftware | phantompdf | < 10.1.1 | Yes |
Operating System | microsoft | windows | - | No |
Application | foxitsoftware | foxit_reader | < 4.1.1 | Yes |
Application | foxitsoftware | phantompdf | < 4.1.1 | Yes |
Operating System | apple | macos | - | No |