CVE-2019-20827: Critical severity foxit phantompdf mac vulnerability
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit PhantomPDF Mac 3.3 and Foxit Reader for Mac before 3.3. It allows stack consumption because of interaction between ICC-Based color space and Alternate color space.
Affected Software
2 affected components
Foxitsoftware Phantompdf Mac<3.3
Foxitsoftware Reader Mac<3.3
Event History
Jun 4, 2020
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-20827.
2
What is the severity of CVE-2019-20827?
The severity of CVE-2019-20827 is critical with a CVSS score of 9.8.
3
Which software versions are affected by CVE-2019-20827?
Foxit PhantomPDF Mac version up to and exclusive of 3.3 and Foxit Reader for Mac version up to and exclusive of 3.3 are affected.
4
How does CVE-2019-20827 occur?
CVE-2019-20827 occurs due to stack consumption caused by the interaction between ICC-Based color space and Alternate color space.
5
Is there a fix available for CVE-2019-20827?
Yes, Foxit Software has released the necessary updates to address the vulnerability. Please refer to their security bulletins for more information.