CVE-2017-6883
—CVSS 3.0
4.7 medium
EPSS
3%p88
Published
()
Modified
Description
The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
- Vendors
- foxitsoftware
- Products
- foxit reader, phantompdf
- Weakness
- CWE-125
- Vector
- CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.