CVE-2021-38563: Out-of-bounds Read
An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It mishandles situations in which an array size (derived from a /Size entry) is smaller than the maximum indirect object number, and thus there is an attempted incorrect array access (leading to a NULL pointer dereference, or out-of-bounds read or write).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-38563?
CVE-2021-38563 is a vulnerability discovered in Foxit PDF Reader and PDF Editor versions before 11.0.1 that mishandles situations where an array size is smaller than the maximum indirect object number, leading to a NULL pointer dereference.
How does CVE-2021-38563 affect Foxit PDF Reader and PDF Editor?
CVE-2021-38563 affects versions of Foxit PDF Reader and PDF Editor before 11.0.1 by allowing an attempted incorrect array access, leading to a NULL pointer dereference.
What is the severity of CVE-2021-38563?
CVE-2021-38563 has a severity rating of 9.8 (Critical).
How can I fix CVE-2021-38563 in Foxit PDF Reader and PDF Editor?
To fix CVE-2021-38563, update your Foxit PDF Reader and PDF Editor to version 11.0.1 or later, which addresses the vulnerability.
Where can I find more information about CVE-2021-38563?
More information about CVE-2021-38563 can be found on the Foxit Software security bulletins page at https://www.foxitsoftware.com/support/security-bulletins.php.