First published: Mon Mar 30 2015(Updated: )
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
foxitsoftware Enterprise Reader | <=7.0.6.1126 | |
Foxit Reader | <=7.0.6.1126 | |
Foxit PhantomPDF | <=7.0.6.1126 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2790 is classified as a denial of service vulnerability that can lead to memory corruption and application crashes.
To mitigate CVE-2015-2790, update to Foxit Reader, Enterprise Reader, or PhantomPDF version 7.1 or later.
CVE-2015-2790 affects Foxit Reader, Enterprise Reader, and PhantomPDF versions prior to 7.1.
Attackers can exploit CVE-2015-2790 to launch denial of service attacks by triggering memory corruption.
Yes, CVE-2015-2790 can be exploited remotely through crafted payloads that manipulate specific data structures.