First published: Fri Apr 22 2016(Updated: )
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted (1) JPEG, (2) GIF, or (3) BMP image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader for Windows | <=7.3.0.118 | |
Foxit Software PhantomPDF for Windows | <=7.3.0.118 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4065 has a severity rating that indicates it can lead to a denial of service due to out-of-bounds read and potential application crashes.
To address CVE-2016-4065, update Foxit Reader or PhantomPDF to version 7.3.4 or later, where the vulnerability is patched.
CVE-2016-4065 can be exploited using specially crafted JPEG, GIF, or BMP image files.
Foxit Reader versions prior to 7.3.4 are affected by CVE-2016-4065 if the gflags app is enabled.
PhantomPDF versions earlier than 7.3.4 are impacted by CVE-2016-4065 when the gflags app is enabled.