CVE-2017-6883: Medium severity Foxitsoftware Foxit Reader vulnerability
The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Foxit Reader (ConvertToPDF plugin) on Windowsto a version that resolves this vulnerability.Fixed in 8.2.1 - Upgrade
Upgrade
PhantomPDF on Windowsto a version that resolves this vulnerability.Fixed in 8.2.1 - Compensating control
On Windows, ensure gflags is not enabled (since the denial-of-service occurs when gflags app is enabled) until Foxit Reader/PhantomPDF are updated.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6883?
CVE-2017-6883 is classified as a denial of service vulnerability, which can cause application crashes.
How do I fix CVE-2017-6883?
To mitigate CVE-2017-6883, you should update to Foxit Reader version 8.2.1 or higher and PhantomPDF version 8.2.1 or higher.
What software is affected by CVE-2017-6883?
CVE-2017-6883 affects Foxit Reader versions up to 8.2.0.2051 and PhantomPDF versions up to 8.2.0.2192 on Windows.
What causes the vulnerability CVE-2017-6883?
CVE-2017-6883 is caused by processing a crafted TIFF image which results in out-of-bounds read leading to application crashes.
Can CVE-2017-6883 lead to information disclosure?
While CVE-2017-6883 primarily causes denial of service, it could indirectly lead to information disclosure due to application instability.