First published: Fri Apr 22 2016(Updated: )
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted FlateDecode stream in a PDF document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader for Windows | <=7.3.0.118 | |
Foxit Software PhantomPDF for Windows | <=7.3.0.118 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4059 is considered high severity as it allows remote attackers to execute arbitrary code.
To mitigate CVE-2016-4059, update Foxit Reader or PhantomPDF to version 7.3.4 or later.
CVE-2016-4059 affects Foxit Reader versions up to and including 7.3.0.118.
CVE-2016-4059 affects PhantomPDF versions up to and including 7.3.0.118.
Yes, CVE-2016-4059 can be exploited by attackers using a crafted FlateDecode stream in a PDF document.