CVE-2016-8878: High severity foxit software phantompdf for windows vulnerability
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted BMP image embedded in the XFA stream in a PDF document, aka "Data from Faulting Address may be used as a return value starting at FOXITREADER."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8878?
CVE-2016-8878 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2016-8878?
To mitigate CVE-2016-8878, users should upgrade Foxit Reader or PhantomPDF to version 8.1 or later.
What versions are affected by CVE-2016-8878?
CVE-2016-8878 affects Foxit Reader and PhantomPDF versions up to 8.0.5 on Windows.
What type of attack is associated with CVE-2016-8878?
CVE-2016-8878 is exploited through a crafted BMP image embedded in a PDF document.
Can CVE-2016-8878 be exploited without user interaction?
Exploitation of CVE-2016-8878 typically requires the user to open a malicious PDF file.