VYPR
Unrated severityNVD Advisory· Published Oct 25, 2019· Updated Aug 5, 2024

CVE-2019-17138

CVE-2019-17138

Description

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion from JPEG to EPS. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-8809.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit Studio Photo 3.6.6.909 has an out-of-bounds read in JPEG-to-EPS conversion, enabling information disclosure via user interaction.

Vulnerability

The vulnerability exists in Foxit Studio Photo version 3.6.6.909 during the conversion from JPEG to EPS format. The specific flaw is an out-of-bounds read caused by improper validation of user-supplied data, resulting in a read past the end of an allocated structure [2]. This code path is reachable when the application processes a specially crafted JPEG file.

Exploitation

An attacker must convince a user to visit a malicious webpage or open a malicious file that triggers the JPEG-to-EPS conversion [2]. No authentication or special privileges are required; user interaction is the sole prerequisite. The attacker supplies crafted data that causes the out-of-bounds read.

Impact

Successful exploitation allows an attacker to disclose sensitive information from the process memory. The ZDI advisory notes that this vulnerability can be leveraged in conjunction with other vulnerabilities to achieve code execution in the context of the current process [2]. The CVSS score is 3.3 (Low), with confidentiality impact limited to low-level information disclosure.

Mitigation

No official fix has been disclosed in the available references. The Foxit security bulletins page [1] does not list a specific update for Foxit Studio Photo. Users should exercise caution when opening untrusted files and consider using alternative software until a patch is released.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.