CVE-2019-20828: Buffer Overflow
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because a looping correction does not occur after JavaScript updates Field APs.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.6
Foxitsoftware Reader<9.6
Remediation
Patch Available
Event History
Jun 4, 2020
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-20828.
2
What is the severity level of CVE-2019-20828?
The severity level of CVE-2019-20828 is high.
3
Which software versions are affected by CVE-2019-20828?
Foxit Reader and PhantomPDF versions before 9.6 are affected by CVE-2019-20828.
4
What is the cause of the vulnerability in CVE-2019-20828?
The vulnerability in CVE-2019-20828 is caused by a buffer overflow.
5
Is there a fix available for CVE-2019-20828?
Yes, it is recommended to update Foxit Reader and PhantomPDF to version 9.6 or above to fix CVE-2019-20828.