![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.810595 |
Category: | General |
Title: | Foxit PhantomPDF Multiple Vulnerabilities (May 2017) - Windows |
Summary: | Foxit PhantomPDF is prone to multiple vulnerabilities. |
Description: | Summary: Foxit PhantomPDF is prone to multiple vulnerabilities. Vulnerability Insight: Multiple flaws exist due to: - An error within the parsing of TIFF images. The issue results from the lack of proper validation of user-supplied data which can result in a read past the end of an allocated object. - Multiple errors within the parsing of fonts in PDF files.The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. Vulnerability Impact: Successful exploitation will allow remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Affected Software/OS: Foxit PhantomPDF version prior to 8.2.1 on windows Solution: Upgrade to Foxit PhantomPDF version 8.2.1 or later. CVSS Score: 6.8 CVSS Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-6883 BugTraq ID: 96870 http://www.securityfocus.com/bid/96870 http://www.zerodayinitiative.com/advisories/ZDI-17-133/ Common Vulnerability Exposure (CVE) ID: CVE-2017-8454 BugTraq ID: 98320 http://www.securityfocus.com/bid/98320 http://www.zerodayinitiative.com/advisories/ZDI-17-135/ Common Vulnerability Exposure (CVE) ID: CVE-2017-8455 BugTraq ID: 98319 http://www.securityfocus.com/bid/98319 http://www.zerodayinitiative.com/advisories/ZDI-17-140/ Common Vulnerability Exposure (CVE) ID: CVE-2017-8453 BugTraq ID: 98317 http://www.securityfocus.com/bid/98317 http://www.zerodayinitiative.com/advisories/ZDI-17-134/ |
Copyright | Copyright (C) 2017 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |