2.6
CVSSv2

CVE-2017-6883

Published: 14/03/2017 Updated: 03/10/2019
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

The ConvertToPDF plugin in Foxit Reader prior to 8.2.1 and PhantomPDF prior to 8.2.1 on Windows, when the gflags app is enabled, allows remote malicious users to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

Vulnerable Product Search on Vulmon Subscribe to Product

foxitsoftware foxit_reader

foxitsoftware phantompdf