Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-8856

Опубликовано: 31 окт. 2016
Источник: nvd
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerability where weak file permissions could be exploited by attackers to execute arbitrary code. After the installation, Foxit Reader's core files were world-writable by default, allowing an attacker to overwrite them with backdoor code, which when executed by privileged user would result in Privilege Escalation, Code Execution, or both.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:mac_os_x:*:*
Версия до 2.1.0.0804 (включая)
cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:linux_kernel:*:*
Версия до 2.1.0.0805 (включая)

EPSS

Процентиль: 0%
0.00007
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-275

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerability where weak file permissions could be exploited by attackers to execute arbitrary code. After the installation, Foxit Reader's core files were world-writable by default, allowing an attacker to overwrite them with backdoor code, which when executed by privileged user would result in Privilege Escalation, Code Execution, or both.

EPSS

Процентиль: 0%
0.00007
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-275