CVE-2017-16813: Input Validation
Published Feb 26, 2018
·Updated
A denial-of-service issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs when a user uploads a file that includes a hexadecimal Unicode character in the "filename" parameter via Wi-Fi, since the app could fail to parse this.
Affected Software
1 affected component
Foxitsoftware Mobilepdf Iphone Os<=6.0.0
Event History
Feb 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16813?
The severity of CVE-2017-16813 is classified as a denial-of-service vulnerability.
2
How does CVE-2017-16813 affect Foxit MobilePDF users?
CVE-2017-16813 affects users by causing the Foxit MobilePDF app to potentially crash when handling specific malformed filenames.
3
What versions of Foxit MobilePDF are impacted by CVE-2017-16813?
Foxit MobilePDF versions prior to 6.1 for iOS are impacted by CVE-2017-16813.
4
How can users mitigate the risks associated with CVE-2017-16813?
Users can mitigate the risks by avoiding the upload of files with hexadecimal Unicode characters in the filename.
5
Is there a patch available for CVE-2017-16813?
Yes, users should update to Foxit MobilePDF version 6.1 or later to resolve CVE-2017-16813.