VYPR
Medium severity5.5NVD Advisory· Published Aug 29, 2022· Updated Jun 17, 2026

CVE-2022-25641

CVE-2022-25641

Description

Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*range: >=11.0,<11.2.2
    • (no CPE)range: <11.2.2
  • cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*range: >=11.0,<11.2.2
    • (no CPE)
    • (no CPE)range: <11.2.2
  • cpe:2.3:a:foxit:phantompdf:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:foxit:phantompdf:*:*:*:*:*:*:*:*range: <10.1.8
    • (no CPE)range: <10.1.8

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.