CVE-2018-20312: Buffer Overflow
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-20312?
CVE-2018-20312 is a vulnerability in Foxit Reader and PhantomPDF that can cause a stack-based buffer overflow or an out-of-bounds read due to a proxyDoAction race condition.
How does CVE-2018-20312 affect Foxit Reader and PhantomPDF?
CVE-2018-20312 affects Foxit Reader versions up to 9.5, PhantomPDF versions up to 8.3.10, and PhantomPDF versions between 9.0 and 9.5.
What is the severity of CVE-2018-20312?
CVE-2018-20312 has a severity rating of 8.1, which is considered high.
How can I fix CVE-2018-20312?
To fix CVE-2018-20312, it is recommended to update to Foxit Reader version 9.5 or newer, or PhantomPDF version 8.3.10 or newer.
Where can I find more information about CVE-2018-20312?
More information about CVE-2018-20312 can be found at the following URL: [https://www.foxitsoftware.com/support/security-bulletins.php](https://www.foxitsoftware.com/support/security-bulletins.php)