Feeds

'Better than Adobe' Foxit PDF plugin hit by worse-than-Adobe 0-day

New security hole: How an evil URL will ruin your day

Build a business case: developing custom apps

A new security bug in the popular Foxit PDF reader plugin for web browsers allows miscreants to compromise computers and install malware. There's no patch for this zero-day vulnerability.

Italian security researcher Andrea Micalizzi discovered that the latest version of the software crashes if users are tricked into clicking on an overly long web link. The plugin is kicked into action by the browser to handle the file and promptly bombs.

But the bug is not triggered by a booby-trapped document, which is the usual way of infecting systems running insecure PDF readers. Instead, clicking on a link to any PDF that deliberately includes a very long query string after the filename causes a buffer overflow in the Foxit plugin.

The offending code, highlighted by Micalizzi, is a simple loop that copies the entire URL into a fixed-sized buffer while scanning for '%' escape codes. By smashing through the end of this buffer, the attacker can arbitrarily overwrite the program's memory and its stack to gain control of the processor.

Versions 5.4.4.1128 and older are affected. The plugin is available for a number of operating systems, including Linux and Symbian, but the bug is at least confirmed in the Microsoft Windows build.

Other security researchers have confirmed the flaw. A proof-of-concept exploit for the hole was not made available in Micalizzi's disclosure.

"The crash, which is a side-effect of a stack overflow, pretty much lets you write to a memory location of your choice," said Paul Ducklin, Sophos's head of technology for Asia Pacific.

Foxit can be installed for Mozilla Firefox, Google Chrome, Opera and Apple Safari. Danish vulnerability management firm Secunia rates the flaw as highly critical. The makers of Foxit - which is billed as "better than Adobe" - have yet to comment on the issue.

Many fans of Foxit have adopted the software as a way of avoiding the not infrequent security problems with Adobe PDF Reader. The appearance of the Firefox plugin vulnerability is further evidence that no software application is immune to security problems. ®

The essential guide to IT transformation

More from The Register

next story
Rupert Murdoch says Google is worse than the NSA
Mr Burns vs. The Chocolate Factory, round three!
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
Think crypto hides you from spooks on Facebook? THINK AGAIN
Traffic fingerprints reveal all, say boffins
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.