CVE-2016-4063: Use After Free
Published Apr 22, 2016
·Updated
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via an object with a revision number of -1 in a PDF document.
Affected Software
2 affected components
Foxitsoftware Foxit Reader Windows<=7.3.0.118
Foxitsoftware Phantompdf Windows<=7.3.0.118
Event History
Apr 22, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4063?
CVE-2016-4063 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2016-4063?
To fix CVE-2016-4063, upgrade Foxit Reader or PhantomPDF to version 7.3.4 or later.
3
What software is affected by CVE-2016-4063?
CVE-2016-4063 affects Foxit Reader and PhantomPDF versions prior to 7.3.4 on Windows.
4
What types of attacks can exploit CVE-2016-4063?
CVE-2016-4063 can be exploited by attackers using specially crafted PDF documents.
5
Who is affected by CVE-2016-4063?
Anyone using vulnerable versions of Foxit Reader or PhantomPDF on Windows is affected by CVE-2016-4063.