PT-2017-13632 · Foxit · Foxit Reader+1
Publicado
2017-09-22
·
Atualizado
2018-01-05
·
CVE-2017-14694
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Foxit Reader versions 8.3.2.25013 and earlier
Foxit PhantomPDF versions 8.3.2.25013 and earlier
Description
The issue allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file. This is related to "Data from Faulting Address controls Code Flow starting at tiptsf!CPenInputPanel::FinalRelease+0x000000000000002f".
Recommendations
For Foxit Reader versions 8.3.2.25013 and earlier, update to a version later than 8.3.2.25013 to resolve the issue.
For Foxit PhantomPDF versions 8.3.2.25013 and earlier, update to a version later than 8.3.2.25013 to resolve the issue.
Exploit
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Foxit Phantompdf
Foxit Reader