CVE-2019-5005: Medium severity foxit reader vulnerability
Published Jan 3, 2019
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.
Affected Software
7 affected components
All of the following
Foxitsoftware Foxit Reader<9.4
Microsoft Windows
All of the following
Foxitsoftware Phantompdf<9.4
Microsoft Windows
Foxitsoftware Foxit Reader<9.4
Microsoft Windows
Foxitsoftware Phantompdf<9.4
Remediation
Patch Available
Event History
Jan 3, 2019
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-5005?
CVE-2019-5005 is classified as a Denial of Service vulnerability that may cause application crashes.
2
How do I fix CVE-2019-5005?
To fix CVE-2019-5005, update Foxit Reader or PhantomPDF to version 9.4 or later.
3
Which software is affected by CVE-2019-5005?
CVE-2019-5005 affects Foxit Reader and PhantomPDF versions before 9.4 on Windows.
4
What type of vulnerability is CVE-2019-5005?
CVE-2019-5005 is a vulnerability that allows for Denial of Service via improper handling of image data.
5
Can CVE-2019-5005 cause data loss?
While CVE-2019-5005 primarily causes application crashes, improper conditions could potentially lead to data loss.