CVE-2016-4060: Use After Free
Published Apr 22, 2016
·Updated
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
Affected Software
2 affected components
Foxitsoftware Foxit Reader Windows<=7.3.0.118
Foxitsoftware Phantompdf Windows<=7.3.0.118
Event History
Apr 22, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4060?
CVE-2016-4060 is rated as a medium severity vulnerability.
2
How do I fix CVE-2016-4060?
To mitigate CVE-2016-4060, upgrade to Foxit Reader or PhantomPDF version 7.3.4 or later.
3
What symptoms indicate an exploitation of CVE-2016-4060?
Exploitation of CVE-2016-4060 may lead to application crashes and denial of service.
4
Is CVE-2016-4060 present in later versions of Foxit Reader?
CVE-2016-4060 has been addressed in Foxit Reader and PhantomPDF version 7.3.4 and later.
5
Which software is affected by CVE-2016-4060?
CVE-2016-4060 affects Foxit Reader and PhantomPDF versions up to 7.3.0.118 on Windows.