First published: Tue Apr 04 2017(Updated: )
Heap-based buffer overflow in the CreateFXPDFConvertor function in ConvertToPdf_x86.dll in Foxit Reader 7.3.4.311 allows remote attackers to execute arbitrary code via a large SamplesPerPixel value in a crafted TIFF image that is mishandled during PDF conversion. This is fixed in 8.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader | =7.3.4.311 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3740 is classified as a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2016-3740, upgrade to Foxit Reader version 8.0 or later.
CVE-2016-3740 affects Foxit Reader version 7.3.4.311 by enabling a heap-based buffer overflow during PDF conversion.
Users of Foxit Reader version 7.3.4.311 are impacted by CVE-2016-3740.
CVE-2016-3740 is associated with a remote code execution attack resulting from processing a specially crafted TIFF image.