PT-2018-6534 · Foxit · Foxit Reader+1

Publicado

2018-04-24

·

Atualizado

2018-06-05

·

CVE-2017-17557

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Foxit Reader versions prior to 9.1 Foxit PhantomPDF versions prior to 9.1
Description: A flaw exists in the parsing of the BITMAPINFOHEADER record in BMP files due to the lack of proper validation of the biSize member. This can result in a heap-based buffer overflow, allowing an attacker to execute code in the context of the current process.
Recommendations: For Foxit Reader versions prior to 9.1, update to version 9.1 or later. For Foxit PhantomPDF versions prior to 9.1, update to version 9.1 or later.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17557

Produtos afetados

Foxit Phantompdf
Foxit Reader