PT-2017-13632 · Foxit · Foxit Reader+1

Publicado

2017-09-22

·

Atualizado

2018-01-05

·

CVE-2017-14694

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit Reader versions 8.3.2.25013 and earlier Foxit PhantomPDF versions 8.3.2.25013 and earlier
Description The issue allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file. This is related to "Data from Faulting Address controls Code Flow starting at tiptsf!CPenInputPanel::FinalRelease+0x000000000000002f".
Recommendations For Foxit Reader versions 8.3.2.25013 and earlier, update to a version later than 8.3.2.25013 to resolve the issue. For Foxit PhantomPDF versions 8.3.2.25013 and earlier, update to a version later than 8.3.2.25013 to resolve the issue.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14694

Produtos afetados

Foxit Phantompdf
Foxit Reader