First published: Thu Jun 04 2020(Updated: )
An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows stack consumption via nested function calls for XML parsing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Phantompdf | <9.7 | |
Foxitsoftware Reader | <9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20819 is a vulnerability discovered in Foxit Reader and PhantomPDF before version 9.7 that allows stack consumption via nested function calls for XML parsing.
Foxit Reader and PhantomPDF versions up to exclusive 9.7 are affected by CVE-2019-20819.
CVE-2019-20819 has a severity rating of 7.5 out of 10, which is considered high.
To fix CVE-2019-20819, it is recommended to update Foxit Reader and PhantomPDF to version 9.7 or later.
More information about CVE-2019-20819 can be found at the following URL: https://www.foxitsoftware.com/support/security-bulletins.php