Information disclosure in Foxit PDF Reader for Windows - CVE-2016-8334

 

Information disclosure in Foxit PDF Reader for Windows - CVE-2016-8334

Published: October 19, 2016 / Updated: October 24, 2016


Vulnerability identifier: #VU1063
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8334
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to obtain potentially sensitive information on the target system.
The weakness is caused by insufficient bounds validation during analysis of JBIG2 segments in PDF file. By convincing a victim to open a specially crafted file, attackers can cause out-of-bounds heap memory condition that lets view important data.
Successful exploitation of the vulnerability results in disclosure of potentially sensitive information.

Affected software

Foxit PDF Reader for Windows

How to mitigate CVE-2016-8334

Update to version 8.1.


External References

Related Security Bulletins