In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a heap-based buffer overflow because dirty image-resource data is mishandled.
| Software | From | Fixed in |
|---|---|---|
| foxitsoftware / phantompdf | - | 9.7.2.29539.x |
| foxitsoftware / phantompdf | - | 10.0.0.35798.x |
| foxitsoftware / reader | - | 10.0.0.35798.x |