RULE(RULE ID:316488)

Rule General Information
Release Date: 2016-04-29
Rule Name: Multiple Foxit Products Multiple Memory Corruption Vulnerabilities -2 (CVE-2015-2790)
Severity:
CVE ID:
Rule Protection Details
Description: Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows
Reference: ExploitDB:36334
ExploitDB:36335
SecurityFocusBID:73430
SecurityTrackerID:1031877
Solutions
The vendor has updated advisory on its official website. Please check it for more information.