Saturday, June 20, 2009

Security Update For Foxit Reader Available

Foxit software has released an update to Foxit Reader 3.0 that fixes following two vulnerabilities:
1. Fixed a problem related to negative stream offset (in malicious JPEG2000 stream) which caused reading data from an out-of-bound address. We have added guard codes to solve this issue.
2. Fixed a problem related to error handling when decoding JPEG2000 header, an uncaught fatal error resulted a subsequent invalid address access. We added error handling code to terminate the decoding process.


Instructions for updating are provided here.

No comments: