CVE-2016-4065: Buffer Overflow
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted (1) JPEG, (2) GIF, or (3) BMP image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4065?
CVE-2016-4065 has a severity rating that indicates it can lead to a denial of service due to out-of-bounds read and potential application crashes.
How do I fix CVE-2016-4065?
To address CVE-2016-4065, update Foxit Reader or PhantomPDF to version 7.3.4 or later, where the vulnerability is patched.
What types of files can exploit CVE-2016-4065?
CVE-2016-4065 can be exploited using specially crafted JPEG, GIF, or BMP image files.
Which versions of Foxit Reader are affected by CVE-2016-4065?
Foxit Reader versions prior to 7.3.4 are affected by CVE-2016-4065 if the gflags app is enabled.
Which versions of PhantomPDF are impacted by CVE-2016-4065?
PhantomPDF versions earlier than 7.3.4 are impacted by CVE-2016-4065 when the gflags app is enabled.