First published: Wed Feb 07 2018(Updated: )
Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (memory corruption and application crash) or potentially execute arbitrary code via the Bezier data in a crafted PDF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader | <=7.3.4.311 | |
Foxit PhantomPDF | <=7.3.4.311 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6169 has been rated as critical due to its potential for remote code execution and denial of service.
To mitigate CVE-2016-6169, update Foxit Reader or PhantomPDF to version 7.3.4.312 or later.
CVE-2016-6169 affects Foxit Reader and PhantomPDF versions 7.3.4.311 and earlier on Windows.
CVE-2016-6169 allows attackers to exploit a heap-based buffer overflow, potentially leading to arbitrary code execution or denial of service.
Yes, there are reports of publicly available exploits targeting CVE-2016-6169.