Foxit Reader FlateDecode Use-After-Free Remote Code Execution Vulnerability

Rocco Calvi

ZDI ID: ZDI-16-394
ZDI-CAN: ZDI-CAN-3671
CVSS
6.8 AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected Vendors
Foxit
Affected Products
Foxit Reader

Additional Details

Disclosure Timeline

  • 2016-04-07 — Vulnerability reported to vendor
  • 2016-06-29 — Coordinated public release of advisory