CVE-2017-8455: High severity foxit reader vulnerability
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8455?
CVE-2017-8455 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2017-8455?
To fix CVE-2017-8455, update Foxit Reader to version 8.2.1 or later and PhantomPDF to version 8.2.1 or later.
What are the risks associated with CVE-2017-8455?
The risks associated with CVE-2017-8455 include exposure of sensitive information and potential remote code execution by attackers.
Which versions of Foxit Reader and PhantomPDF are affected by CVE-2017-8455?
CVE-2017-8455 affects Foxit Reader versions up to 8.2.0.2051 and PhantomPDF versions up to 8.2.0.2192.
Can CVE-2017-8455 be exploited through malicious PDF files?
Yes, CVE-2017-8455 can be exploited by attackers through crafted fonts in malicious PDF documents.