PT-2016-5834 · Microsoft+1 · Gflags+3

Abdulaziz Hariri

·

Publicado

2016-03-23

·

Atualizado

2016-11-08

·

CVE-2016-4065

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit Reader and PhantomPDF versions prior to 7.3.4
Description The issue allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted image, including JPEG, GIF, or BMP formats. This occurs when the gflags app is enabled.
Recommendations For Foxit Reader and PhantomPDF versions prior to 7.3.4, update to version 7.3.4 or later to resolve the issue. As a temporary workaround, consider disabling the ConvertToPDF plugin until a patch is available. Restrict access to the ConvertToPDF functionality to minimize the risk of exploitation. Avoid using the ConvertToPDF plugin with untrusted image files, including JPEG, GIF, and BMP formats, until the issue is resolved.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-4065
ZDI-16-216
ZDI-16-217
ZDI-16-218

Produtos afetados

Converttopdf
Foxit Reader
Phantompdf
Gflags