First published: Mon Dec 24 2018(Updated: )
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow.
Credit: cve@checkpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Quick PDF Library | <16.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20247 has a high severity rating due to the potential for a stack overflow from processing malicious PDFs.
To fix CVE-2018-20247, upgrade Foxit Quick PDF Library to version 16.12 or later.
All versions of Foxit Quick PDF Library prior to 16.12 are affected by CVE-2018-20247.
The LoadFromFile, LoadFromString, and LoadFromStream functions are vulnerable in CVE-2018-20247.
CVE-2018-20247 facilitates a stack overflow attack through a malformed PDF with a recursive page tree structure.