First published: Thu Jan 03 2019(Updated: )
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds Read Information Disclosure and crash due to a NULL pointer dereference when reading TIFF data during TIFF parsing.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader | <9.4 | |
Microsoft Windows | ||
Foxit PhantomPDF | <9.4 | |
All of | ||
Foxit Reader | <9.4 | |
Microsoft Windows | ||
All of | ||
Foxit PhantomPDF | <9.4 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5007 is rated as medium severity due to its potential for information disclosure and crashes.
To fix CVE-2019-5007, update Foxit Reader and PhantomPDF to version 9.4 or later.
CVE-2019-5007 is an Out-of-Bounds Read vulnerability leading to information disclosure and crashes.
CVE-2019-5007 affects Foxit Reader and PhantomPDF versions prior to 9.4 on Windows.
The issue in CVE-2019-5007 is caused by a NULL pointer dereference when parsing TIFF data.