CVE-2016-8877: Buffer Overflow
Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted JPEG2000 image embedded in a PDF document, aka a "corrupted suffix pattern" issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8877?
CVE-2016-8877 has a critical severity level due to the potential for remote code execution by attackers.
How do I fix CVE-2016-8877?
To fix CVE-2016-8877, update Foxit Reader and PhantomPDF to versions 8.1 or later.
What products are affected by CVE-2016-8877?
CVE-2016-8877 affects Foxit Reader and PhantomPDF versions up to and including 8.0.5 on Windows.
What type of vulnerability is CVE-2016-8877?
CVE-2016-8877 is a heap buffer overflow vulnerability that allows for out-of-bounds write operations.
What is the attack vector for CVE-2016-8877?
The attack vector for CVE-2016-8877 involves remote attackers exploiting a crafted JPEG2000 image embedded in a PDF document.