Vulnerability Description
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foxitsoftware | Enterprise Reader | <= 7.1.3.320 |
| Foxitsoftware | Foxit Reader | <= 7.1.3.320 |
| Foxitsoftware | Phantompdf | <= 7.1.3.320 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/131685/Foxit-Reader-7.1.3.320-Memory-CorrupExploitThird Party AdvisoryVDB Entry
- http://protekresearchlab.com/PRL-2015-05/Exploit
- http://www.foxitsoftware.com/support/security_bulletins.php#FRD-27Vendor Advisory
- http://www.securityfocus.com/bid/74418
- http://www.securitytracker.com/id/1032229Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/36859/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/131685/Foxit-Reader-7.1.3.320-Memory-CorrupExploitThird Party AdvisoryVDB Entry
- http://protekresearchlab.com/PRL-2015-05/Exploit
- http://www.foxitsoftware.com/support/security_bulletins.php#FRD-27Vendor Advisory
- http://www.securityfocus.com/bid/74418
- http://www.securitytracker.com/id/1032229Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/36859/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2015-3632?
CVE-2015-3632 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.
How severe is CVE-2015-3632?
CVE-2015-3632 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-3632?
Check the references section above for vendor advisories and patch information. Affected products include: Foxitsoftware Enterprise Reader, Foxitsoftware Foxit Reader, Foxitsoftware Phantompdf.