CVE-2016-8876: High severity foxit software phantompdf for windows vulnerability
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read Access Violation starting at FoxitReader."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8876?
CVE-2016-8876 is classified as a high severity vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2016-8876?
To fix CVE-2016-8876, you should update Foxit Reader or PhantomPDF to version 8.1 or later.
What software is affected by CVE-2016-8876?
CVE-2016-8876 affects Foxit Reader and PhantomPDF versions prior to 8.1 on Windows.
What type of attacks can exploit CVE-2016-8876?
CVE-2016-8876 can be exploited by attackers using a specially crafted TIFF image embedded in a PDF document.
What are the potential consequences of CVE-2016-8876?
Exploiting CVE-2016-8876 can lead to arbitrary code execution on the victim's system.