CVE-2018-20247: High severity foxit quick pdf library vulnerability
Published Dec 24, 2018
·Updated
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow.
Affected Software
1 affected component
Foxitsoftware Quick Pdf Library<16.12
Event History
Dec 24, 2018
CVE Published
06:29 PM
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-20247?
CVE-2018-20247 has a high severity rating due to the potential for a stack overflow from processing malicious PDFs.
2
How do I fix CVE-2018-20247?
To fix CVE-2018-20247, upgrade Foxit Quick PDF Library to version 16.12 or later.
3
What are the affected versions in CVE-2018-20247?
All versions of Foxit Quick PDF Library prior to 16.12 are affected by CVE-2018-20247.
4
What functions are vulnerable in CVE-2018-20247?
The LoadFromFile, LoadFromString, and LoadFromStream functions are vulnerable in CVE-2018-20247.
5
What type of attack does CVE-2018-20247 facilitate?
CVE-2018-20247 facilitates a stack overflow attack through a malformed PDF with a recursive page tree structure.