CVE-2016-4059: Use After Free
Published Apr 22, 2016
·Updated
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted FlateDecode stream in a PDF document.
Affected Software
2 affected components
Foxitsoftware Foxit Reader Windows<=7.3.0.118
Foxitsoftware Phantompdf Windows<=7.3.0.118
Event History
Apr 22, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4059?
CVE-2016-4059 is considered high severity as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2016-4059?
To mitigate CVE-2016-4059, update Foxit Reader or PhantomPDF to version 7.3.4 or later.
3
Which versions of Foxit Reader are affected by CVE-2016-4059?
CVE-2016-4059 affects Foxit Reader versions up to and including 7.3.0.118.
4
Which versions of PhantomPDF are affected by CVE-2016-4059?
CVE-2016-4059 affects PhantomPDF versions up to and including 7.3.0.118.
5
Can CVE-2016-4059 be exploited via a PDF document?
Yes, CVE-2016-4059 can be exploited by attackers using a crafted FlateDecode stream in a PDF document.