Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-25641


Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.


Published

2022-08-29T05:15:08.213

Last Modified

2024-11-21T06:52:29.473

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application foxit pdf_editor < 11.2.2 Yes
Application foxit pdf_reader < 11.2.2 Yes
Application foxit phantompdf < 10.1.8 Yes
Operating System microsoft windows - No

References