PT-2017-13632 · Foxit · Foxit Reader+1

Published

2017-09-22

·

Updated

2018-01-05

·

CVE-2017-14694

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit Reader versions 8.3.2.25013 and earlier Foxit PhantomPDF versions 8.3.2.25013 and earlier
Description The issue allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file. This is related to "Data from Faulting Address controls Code Flow starting at tiptsf!CPenInputPanel::FinalRelease+0x000000000000002f".
Recommendations For Foxit Reader versions 8.3.2.25013 and earlier, update to a version later than 8.3.2.25013 to resolve the issue. For Foxit PhantomPDF versions 8.3.2.25013 and earlier, update to a version later than 8.3.2.25013 to resolve the issue.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14694

Affected Products

Foxit Phantompdf
Foxit Reader