Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.810595
Category:General
Title:Foxit PhantomPDF Multiple Vulnerabilities (May 2017) - Windows
Summary:Foxit PhantomPDF is prone to multiple vulnerabilities.
Description:Summary:
Foxit PhantomPDF is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- An error within the parsing of TIFF images. The issue results from the lack
of proper validation of user-supplied data which can result in a read past
the end of an allocated object.

- Multiple errors within the parsing of fonts in PDF files.The issue results
from the lack of proper validation of user-supplied data, which can result
in a read past the end of an allocated object.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to cause a denial of service (out-of-bounds read and application crash)
via a crafted TIFF image. The vulnerability could lead to information disclosure.
An attacker can leverage this in conjunction with other vulnerabilities to execute
code in the context of the current process.

Affected Software/OS:
Foxit PhantomPDF version prior to 8.2.1 on
windows

Solution:
Upgrade to Foxit PhantomPDF version 8.2.1 or
later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-6883
BugTraq ID: 96870
http://www.securityfocus.com/bid/96870
http://www.zerodayinitiative.com/advisories/ZDI-17-133/
Common Vulnerability Exposure (CVE) ID: CVE-2017-8454
BugTraq ID: 98320
http://www.securityfocus.com/bid/98320
http://www.zerodayinitiative.com/advisories/ZDI-17-135/
Common Vulnerability Exposure (CVE) ID: CVE-2017-8455
BugTraq ID: 98319
http://www.securityfocus.com/bid/98319
http://www.zerodayinitiative.com/advisories/ZDI-17-140/
Common Vulnerability Exposure (CVE) ID: CVE-2017-8453
BugTraq ID: 98317
http://www.securityfocus.com/bid/98317
http://www.zerodayinitiative.com/advisories/ZDI-17-134/
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.