CVE-2020-11493: High severity foxit phantompdf vulnerability
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-11493.
What is the severity of CVE-2020-11493?
The severity of CVE-2020-11493 is high with a severity value of 8.1.
Which software versions are affected by CVE-2020-11493?
Foxit Reader versions before 10.0.1, PhantomPDF versions before 10.0.1 and 9.7.3 are affected by CVE-2020-11493.
How can attackers obtain sensitive information in CVE-2020-11493?
Attackers can obtain sensitive information in CVE-2020-11493 by exploiting an uninitialized object in Foxit Reader and PhantomPDF.
Is Microsoft Windows vulnerable to CVE-2020-11493?
No, Microsoft Windows is not vulnerable to CVE-2020-11493.
Where can I find more information about CVE-2020-11493?
You can find more information about CVE-2020-11493 on the Foxit Software security bulletins page at https://www.foxitsoftware.com/support/security-bulletins.php.