First published: Mon Oct 31 2016(Updated: )
Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted JPEG2000 image embedded in a PDF document, aka a "corrupted suffix pattern" issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Software PhantomPDF for Windows | <=8.0.5 | |
Foxit Reader | <=8.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8877 has a critical severity level due to the potential for remote code execution by attackers.
To fix CVE-2016-8877, update Foxit Reader and PhantomPDF to versions 8.1 or later.
CVE-2016-8877 affects Foxit Reader and PhantomPDF versions up to and including 8.0.5 on Windows.
CVE-2016-8877 is a heap buffer overflow vulnerability that allows for out-of-bounds write operations.
The attack vector for CVE-2016-8877 involves remote attackers exploiting a crafted JPEG2000 image embedded in a PDF document.