CVE-2019-5007: Null Pointer Dereference
Published Jan 3, 2019
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds Read Information Disclosure and crash due to a NULL pointer dereference when reading TIFF data during TIFF parsing.
Affected Software
7 affected components
All of the following
Foxitsoftware Foxit Reader<9.4
Microsoft Windows
All of the following
Foxitsoftware Phantompdf<9.4
Microsoft Windows
Foxitsoftware Foxit Reader<9.4
Microsoft Windows
Foxitsoftware Phantompdf<9.4
Remediation
Patch Available
Event History
Jan 3, 2019
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-5007?
CVE-2019-5007 is rated as medium severity due to its potential for information disclosure and crashes.
2
How do I fix CVE-2019-5007?
To fix CVE-2019-5007, update Foxit Reader and PhantomPDF to version 9.4 or later.
3
What type of vulnerability is CVE-2019-5007?
CVE-2019-5007 is an Out-of-Bounds Read vulnerability leading to information disclosure and crashes.
4
Which software versions are affected by CVE-2019-5007?
CVE-2019-5007 affects Foxit Reader and PhantomPDF versions prior to 9.4 on Windows.
5
What causes the issue in CVE-2019-5007?
The issue in CVE-2019-5007 is caused by a NULL pointer dereference when parsing TIFF data.