CVE-2016-6168: Use After Free
Published Feb 7, 2018
·Updated
Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a crafted PDF file.
Affected Software
2 affected components
Foxitsoftware Foxit Reader<=7.3.4.311
Foxitsoftware Phantompdf<=7.3.4.311
Event History
Feb 7, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6168?
CVE-2016-6168 has a severity rating of critical due to its potential for exploitation leading to arbitrary code execution.
2
How do I fix CVE-2016-6168?
To fix CVE-2016-6168, update Foxit Reader or PhantomPDF to the latest version beyond 7.3.4.311.
3
What types of attacks can exploit CVE-2016-6168?
CVE-2016-6168 can be exploited through crafted PDF files that induce a use-after-free condition.
4
Which versions of Foxit Reader are affected by CVE-2016-6168?
Foxit Reader versions up to and including 7.3.4.311 are affected by CVE-2016-6168.
5
Which versions of Foxit PhantomPDF are affected by CVE-2016-6168?
Foxit PhantomPDF versions up to and including 7.3.4.311 are affected by CVE-2016-6168.