CVE-2018-21240: High severity foxit phantompdf vulnerability
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via an ArrayBuffer(0xfffffffe) call.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.2
Foxitsoftware Reader<9.2
Event History
Jun 4, 2020
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-21240.
2
What software versions are affected by this vulnerability?
Foxit Reader and PhantomPDF versions up to 9.2 are affected by this vulnerability.
3
What is the severity of CVE-2018-21240?
CVE-2018-21240 has a severity rating of 7.5 (high).
4
How does CVE-2018-21240 affect memory consumption?
CVE-2018-21240 allows memory consumption via an ArrayBuffer(0xfffffffe) call.
5
How can I fix the vulnerability CVE-2018-21240?
To fix CVE-2018-21240, users should update to Foxit Reader and PhantomPDF version 9.2 or above.