CVE-2019-20820: Null Pointer Dereference
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference during the parsing of file data.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.7
Foxitsoftware Reader<9.7
Remediation
Patch Available
Event History
Jun 4, 2020
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
Description
Frequently Asked Questions
1
What is CVE-2019-20820?
CVE-2019-20820 is a vulnerability in Foxit Reader and PhantomPDF before 9.7 that allows a NULL pointer dereference during the parsing of file data.
2
How does CVE-2019-20820 impact Foxit Reader and PhantomPDF?
CVE-2019-20820 allows an attacker to trigger a NULL pointer dereference, which could lead to a denial-of-service condition or potentially remote code execution.
3
What is the severity of CVE-2019-20820?
The severity of CVE-2019-20820 is classified as high with a CVSS score of 7.5.
4
Which versions of Foxit Reader and PhantomPDF are affected by CVE-2019-20820?
Foxit Reader and PhantomPDF versions up to but excluding 9.7 are affected by CVE-2019-20820.
5
How can I fix CVE-2019-20820?
To fix CVE-2019-20820, users should update Foxit Reader and PhantomPDF to version 9.7 or later.