Medium severity5.5NVD Advisory· Published Aug 29, 2022· Updated Jun 17, 2026
CVE-2022-25641
CVE-2022-25641
Description
Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*range: >=11.0,<11.2.2
- (no CPE)range: <11.2.2
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*range: >=11.0,<11.2.2
- (no CPE)
- (no CPE)range: <11.2.2
cpe:2.3:a:foxit:phantompdf:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:foxit:phantompdf:*:*:*:*:*:*:*:*range: <10.1.8
- (no CPE)range: <10.1.8
Patches
Vulnerability mechanics
References
1- www.foxit.com/support/security-bulletins.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.