CVE-2018-20311: Buffer Overflow
Published Jan 7, 2021
·Updated
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
Affected Software
3 affected components
Foxitsoftware Phantompdf<8.3.10
Foxitsoftware Phantompdf>=9.0<9.5
Foxitsoftware Reader<9.5
Event History
Jan 7, 2021
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-20311.
2
What software versions are affected by this vulnerability?
Foxit Reader versions before 9.5, PhantomPDF versions before 8.3.10 and 9.x before 9.5 are affected.
3
What is the severity of CVE-2018-20311?
The severity of CVE-2018-20311 is high with a CVSS score of 8.1.
4
What is the description of this vulnerability?
The vulnerability in Foxit Reader and PhantomPDF is caused by a race condition that can lead to a stack-based buffer overflow or an out-of-bounds read.
5
How can I fix the vulnerability in Foxit Reader and PhantomPDF?
To fix the vulnerability, it is recommended to update to the latest version of Foxit Reader (9.5 or above) and PhantomPDF (8.3.10 or above).