First published: Fri Sep 04 2020(Updated: )
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after splitting a string into two parts. A crash may also occur.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Phantompdf | <=9.7.2.29539 | |
Microsoft Windows | ||
Foxitsoftware Phantompdf | <=10.0.0.35798 | |
Foxitsoftware Reader | <=10.0.0.35798 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-12247.
The severity of CVE-2020-12247 is high with a severity value of 7.1.
Foxit Reader and PhantomPDF versions before 10.0.1 and PhantomPDF versions before 9.7.3 are affected by CVE-2020-12247.
Attackers can exploit CVE-2020-12247 to obtain sensitive information from an out-of-bounds read by continuing to use a text-string index after splitting a string into two parts.
Yes, you can find additional information about CVE-2020-12247 in the security bulletins on the Foxit Software support page.