CVE-2018-20315: Buffer Overflow
Published Jan 7, 2021
·Updated
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
Affected Software
3 affected components
Foxitsoftware Phantompdf<8.3.10
Foxitsoftware Phantompdf>=9.0<9.5
Foxitsoftware Reader<9.5
Event History
Jan 7, 2021
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-20315.
2
What software versions are affected by CVE-2018-20315?
Foxit Reader versions before 9.5, PhantomPDF versions before 8.3.10, and PhantomPDF 9.x versions before 9.5 are affected.
3
What is the severity of CVE-2018-20315?
The severity of CVE-2018-20315 is high.
4
What is the risk associated with CVE-2018-20315?
CVE-2018-20315 can cause a stack-based buffer overflow or an out-of-bounds read.
5
How can I fix CVE-2018-20315?
To fix CVE-2018-20315, update Foxit Reader to version 9.5 or later, update PhantomPDF to version 8.3.10 or later, or update PhantomPDF 9.x to version 9.5 or later.