CVE-2016-4062

Description

Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote attackers to cause a denial of service (application hang) via a crafted PDF.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.038

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Foxit Reader Enterprise 7.3.0.118 to latest versionWindows
Upgrade foxit_reader 7.3.0.118 to latest versionWindows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 8 (ML) 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 8 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 9 (EXE) 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 9 (ML) (EXE) 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 9 (ML) (MSI) 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 9 (MSI) 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF Slim 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit Reader 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit Reader Enterprise 7.3.0.118Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-341798Foxit PDF Reader (MSI) (2024.3.0.26795) (Formerly Foxit Reader Enterprise)
PATCH-341796Foxit Reader (2024.3.0.26795)
PATCH-311706Foxit PhantomPDF 8 ML (8.3.12.47136)
PATCH-311625Foxit PhantomPDF 8 (8.3.12.47136)
PATCH-317726Foxit PhantomPDF 9 (EXE) (9.7.5.29616)
PATCH-317727Foxit PhantomPDF 9 (ML) (EXE) (9.7.5.29616)
PATCH-317728Foxit PhantomPDF 9 (ML) (MSI) (9.7.5.29616)
PATCH-317729Foxit PhantomPDF 9 (MSI) (9.7.5.29616)
PATCH-306313Foxit PhantomPDF (MSI) (8.3.2) (Formerly Foxit PhantomPDF Slim)
PATCH-347386Foxit Reader (2025.1.0.27937)
PATCH-347385Foxit PDF Reader (MSI) (2025.1.0.27937)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234