First published: Wed Feb 07 2018(Updated: )
Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a crafted PDF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader | <=7.3.4.311 | |
Foxit PhantomPDF | <=7.3.4.311 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6168 has a severity rating of critical due to its potential for exploitation leading to arbitrary code execution.
To fix CVE-2016-6168, update Foxit Reader or PhantomPDF to the latest version beyond 7.3.4.311.
CVE-2016-6168 can be exploited through crafted PDF files that induce a use-after-free condition.
Foxit Reader versions up to and including 7.3.4.311 are affected by CVE-2016-6168.
Foxit PhantomPDF versions up to and including 7.3.4.311 are affected by CVE-2016-6168.