CVE-2019-13124

Description

Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack memory because of Uncontrolled Recursion in the V8 JavaScript engine (issue 2 of 2).

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.032

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-5031,CVE-2019-13123,CVE-2019-13124,CVE-2019-17183 are fixed in Foxit PhantomPDF 8 ML (8.3.12.47136)Windows
Vulnerabilities CVE-2019-5031,CVE-2019-13123,CVE-2019-13124,CVE-2019-17183 are fixed in Foxit PhantomPDF 8 (8.3.12.47136)Windows
Vulnerabilities CVE-2019-5031,CVE-2019-13123,CVE-2019-13124,CVE-2019-17183 are fixed in Foxit Reader (9.7.0.29455)Windows
Vulnerabilities CVE-2019-5031,CVE-2019-13123,CVE-2019-13124,CVE-2019-17183 are fixed in Foxit Reader Enterprise (9.7.0.29455)Windows
Vulnerabilities CVE-2019-5031,CVE-2019-13123,CVE-2019-13124,CVE-2019-17183 are fixed in Foxit PhantomPDF Business 9 ML (9.7.0.29478)Windows
Vulnerabilities CVE-2019-5031,CVE-2019-13123,CVE-2019-13124,CVE-2019-17183 are fixed in Foxit PhantomPDF Business 9 (9.7.0.29478)Windows
Vulnerabilities CVE-2019-5031,CVE-2019-13123,CVE-2019-13124,CVE-2019-17183 are fixed in Foxit PhantomPDF Business 9 (ML) (EXE) (9.7.0.29478)Windows
Vulnerabilities CVE-2019-5031,CVE-2019-13123,CVE-2019-13124,CVE-2019-17183 are fixed in Foxit PhantomPDF Business 9 (EXE) (9.7.0.29478)Windows
Multiple vulnerabilities fixed in Update For Foxit Reader (7.3.4.0311)Windows
Multiple vulnerabilities are fixed in Foxit Reader (9.7.1.29511)Windows
Multiple vulnerabilities are fixed in Foxit Reader Enterprise (9.7.1.29511)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-311706Foxit PhantomPDF 8 ML (8.3.12.47136)
PATCH-311625Foxit PhantomPDF 8 (8.3.12.47136)
PATCH-311097Foxit Reader (9.7.0.29455)
PATCH-311099Foxit Reader Enterprise (9.7.0.29455)
PATCH-311339Foxit PhantomPDF Business 9 (ML) (MSI) (9.7.0.29478)
PATCH-311338Foxit PhantomPDF Business 9 (MSI) (9.7.0.29478)
PATCH-312353Foxit PhantomPDF Business 9 (ML) (EXE) (9.7.0.29478)
PATCH-312352Foxit PhantomPDF Business 9 (EXE) (9.7.0.29478)
PATCH-303284Update For Foxit Reader (7.3.4.0311)
PATCH-347386Foxit Reader (2025.1.0.27937)
PATCH-347385Foxit PDF Reader (MSI) (2025.1.0.27937)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234