Vulnerability Description
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL starting at FoxitReader!safe_vsnprintf+0x00000000002c4330" issue.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foxitsoftware | Foxit Reader | 9.3.0.10826 |
| Foxitsoftware | U3D | 9.3.0.10809 |
Related Weaknesses (CWE)
References
- https://github.com/Yan-1-20/Yan-1-20.github.io/blob/master/2018/11/02/2018/11/20Broken LinkThird Party Advisory
- https://github.com/Yan-1-20/Yan-1-20.github.io/blob/master/2018/11/10/2018/11/20Broken LinkThird Party Advisory
- https://yan-1-20.github.io/2018/11/02/2018/11/2018-11-02/Broken LinkThird Party Advisory
- https://yan-1-20.github.io/2018/11/10/2018/11/2018-11-10/Broken LinkThird Party Advisory
- https://www.foxitsoftware.com/support/security-bulletins.phpPatchVendor Advisory
- https://github.com/Yan-1-20/Yan-1-20.github.io/blob/master/2018/11/02/2018/11/20Broken LinkThird Party Advisory
- https://github.com/Yan-1-20/Yan-1-20.github.io/blob/master/2018/11/10/2018/11/20Broken LinkThird Party Advisory
- https://yan-1-20.github.io/2018/11/02/2018/11/2018-11-02/Broken LinkThird Party Advisory
- https://yan-1-20.github.io/2018/11/10/2018/11/2018-11-10/Broken LinkThird Party Advisory
FAQ
What is CVE-2018-18933?
CVE-2018-18933 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive inf...
How severe is CVE-2018-18933?
CVE-2018-18933 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-18933?
Check the references section above for vendor advisories and patch information. Affected products include: Foxitsoftware Foxit Reader, Foxitsoftware U3D.