First published: Thu Jan 07 2021(Updated: )
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Phantompdf | <8.3.10 | |
Foxitsoftware Phantompdf | >=9.0<9.5 | |
Foxitsoftware Reader | <9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20313 is a vulnerability in Foxit Reader and PhantomPDF software versions before 9.5 that can lead to a stack-based buffer overflow or an out-of-bounds read.
Foxit Reader versions before 9.5, PhantomPDF versions before 8.3.10, and PhantomPDF versions between 9.0 and 9.5 are affected by CVE-2018-20313.
CVE-2018-20313 has a severity score of 8.1, which is considered high.
To fix CVE-2018-20313, update Foxit Reader to version 9.5 or later, and update PhantomPDF to version 8.3.10 or later if using versions before 9.0, or version 9.5 or later if using versions between 9.0 and 9.5.
You can find more information about CVE-2018-20313 in the security bulletins provided by Foxit Software at https://www.foxitsoftware.com/support/security-bulletins.php.