ZeroHour

CVE-2017-6883

CVSS 3.0
4.7 medium
EPSS
3%p88
Published
()
Modified
Description

The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

Vendors
foxitsoftware
Products
foxit reader, phantompdf
Weakness
CWE-125
Vector
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.