CVE-2019-20837: High severity foxit phantompdf vulnerability
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It allows signature validation bypass via a modified file or a file with non-standard signatures.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.5
Foxitsoftware Reader<9.5
Remediation
Patch Available
Event History
Jun 4, 2020
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-20837.
2
What is the affected software?
The affected software includes Foxit Reader and PhantomPDF versions up to and exclusive of 9.5.
3
What is the severity of CVE-2019-20837?
The severity of CVE-2019-20837 is high (CVSS score: 7.5).
4
How does CVE-2019-20837 work?
CVE-2019-20837 allows signature validation bypass through a modified file or a file with non-standard signatures.
5
Is there a fix available for CVE-2019-20837?
Yes, a fix is available. Users should update their Foxit Reader and PhantomPDF software to version 9.5 or above.