Foxit PDF Reader 0day Îó²î
2017-08-18
×î½ü£¬Çå¾²Ñо¿Ö°Ô±ÔÚFoxit pdf Reader·¢Ã÷Á½¸öÑÏÖØµÄÇå¾²Îó²î£¬Îó²î±àºÅ»®·ÖΪCVE-2017-10951ºÍCVE-2017-10952¡£
CVE-2017-10951£º
¸ÃÎó²îÊÇÒ»¸öÏÂÁî×¢ÈëµÄÎó²î£¬Ôµ¹ÊÔÓÉÊÇÓÉÓÚapp.launchURLº¯ÊýȱÉÙÊʵ±µÄÑéÖ¤»áÖ´Ðй¥»÷ÕßÌṩµÄ×Ö·û´®¡£
CVE-2017-10952£º
¸ÃÎó²îÊÇí§ÒâÎļþдÎó²î£¬ÄÜÈù¥»÷ÕßÔÚÄ¿µÄϵͳдÈëí§ÒâÎļþ£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î»ñÈ¡´úÂëÖ´ÐÐÄÜÁ¦¡£
ÕâÁ½¸öÎó²î¶¼Äܵ¼ÖÂí§Òâ´úÂëÖ´ÐУ¬²»¹ýFoxit¹«Ë¾¾Ü¾ø¶ÔÕâÁ½¸öÎó²îÌṩ²¹¶¡£¬ÓÉÓÚFoxit pdf ReaderµÄÇå¾²ÔĶÁģʽÊÇĬÈÏ¿ªÆôµÄ£¬Îó²î²»»á¶ÔĬÈÏÉèÖõÄFoxit pdf ReaderÔì³ÉÓ°Ïì¡£²»¹ýδÀ´ÈôÊǹ¥»÷ÕßÕÒµ½ÈƹýÇå¾²ÔĶÁģʽµÄÒªÁ죬ÒÔÉÏÎó²î¿ÉÄܱ»´ó¹æÄ£Ê¹Óá£
Ïà¹ØµØµã£º
http://thehackernews.com/2017/08/two-critical-zero-day-flaws-disclosed.html
https://www.zerodayinitiative.com/blog/2017/8/17/busting-myths-in-foxit-reader
ÊÜÓ°ÏìµÄ°æ±¾
Foxit pdf Reader
¹æ±Ü¼Æ»®
¡¤ ²»Òª·¿ªÈκÎȪԴ²»Ã÷µÄpdfÎĵµ£»
¡¤ Foxit pdf ReaderµÄÇå¾²ÔĶÁģʽҪ¼á³Ö·¿ª×´Ì¬¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ





