Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6883

Опубликовано: 14 мар. 2017
Источник: nvd
CVSS3: 4.7
CVSS2: 2.6
EPSS Низкий

Описание

The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:*
Версия до 8.2.0.2051 (включая)
cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:*
Версия до 8.2.0.2192 (включая)
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

EPSS

Процентиль: 32%
0.00123
Низкий

4.7 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 4.7
github
больше 3 лет назад

The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

EPSS

Процентиль: 32%
0.00123
Низкий

4.7 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-125