CVE-2016-4062: Medium severity foxit reader for windows vulnerability
Published Apr 22, 2016
·Updated
Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote attackers to cause a denial of service (application hang) via a crafted PDF.
Affected Software
2 affected components
Foxitsoftware Foxit Reader Windows<=7.3.0.118
Foxitsoftware Phantompdf Windows<=7.3.0.118
Event History
Apr 22, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4062?
CVE-2016-4062 is classified as a denial of service vulnerability that can cause application hangs.
2
How do I fix CVE-2016-4062?
To fix CVE-2016-4062, upgrade Foxit Reader or PhantomPDF to version 7.3.4 or later.
3
What versions are affected by CVE-2016-4062?
CVE-2016-4062 affects Foxit Reader and PhantomPDF versions prior to 7.3.4 on Windows.
4
Can CVE-2016-4062 be exploited remotely?
Yes, CVE-2016-4062 can be exploited remotely through a crafted PDF file.
5
What impact does CVE-2016-4062 have on users?
CVE-2016-4062 can lead to application hangs, resulting in a denial of service for users.