CVE-2015-2790: Input Validation
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2790?
CVE-2015-2790 is classified as a denial of service vulnerability that can lead to memory corruption and application crashes.
How do I fix CVE-2015-2790?
To mitigate CVE-2015-2790, update to Foxit Reader, Enterprise Reader, or PhantomPDF version 7.1 or later.
Which versions of Foxit software are affected by CVE-2015-2790?
CVE-2015-2790 affects Foxit Reader, Enterprise Reader, and PhantomPDF versions prior to 7.1.
What types of attacks are possible with CVE-2015-2790?
Attackers can exploit CVE-2015-2790 to launch denial of service attacks by triggering memory corruption.
Can CVE-2015-2790 be exploited remotely?
Yes, CVE-2015-2790 can be exploited remotely through crafted payloads that manipulate specific data structures.