CVE-2018-1179 is a sensitive information disclosure vulnerability affecting Foxit Reader 9.0.0.29935 and PhantomPDF. It stems from improper validation of DataSubBlock structures in GIF images, leading to a read past the end of an allocated data structure. Rated Medium (CVSS 6.5), exploitation requires user interaction, such as visiting a malicious page or opening a malicious file, and could potentially lead to code execution when chained with other vulnerabilities. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed on the CISA KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0.1.1049CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:* | ||
<= 9.0.1.1049CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.