CVE-2019-20819: High severity foxit phantompdf vulnerability
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows stack consumption via nested function calls for XML parsing.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.7
Foxitsoftware Reader<9.7
Remediation
Patch Available
Event History
Jun 4, 2020
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
Description
Frequently Asked Questions
1
What is CVE-2019-20819?
CVE-2019-20819 is a vulnerability discovered in Foxit Reader and PhantomPDF before version 9.7 that allows stack consumption via nested function calls for XML parsing.
2
Which software is affected by CVE-2019-20819?
Foxit Reader and PhantomPDF versions up to exclusive 9.7 are affected by CVE-2019-20819.
3
What is the severity of CVE-2019-20819?
CVE-2019-20819 has a severity rating of 7.5 out of 10, which is considered high.
4
How can I fix CVE-2019-20819?
To fix CVE-2019-20819, it is recommended to update Foxit Reader and PhantomPDF to version 9.7 or later.
5
Where can I find more information about CVE-2019-20819?
More information about CVE-2019-20819 can be found at the following URL: https://www.foxitsoftware.com/support/security-bulletins.php