CVE-2020-12247: High severity foxit phantompdf vulnerability
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after splitting a string into two parts. A crash may also occur.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-12247.
What is the severity of CVE-2020-12247?
The severity of CVE-2020-12247 is high with a severity value of 7.1.
Which software versions are affected by CVE-2020-12247?
Foxit Reader and PhantomPDF versions before 10.0.1 and PhantomPDF versions before 9.7.3 are affected by CVE-2020-12247.
How can attackers exploit CVE-2020-12247?
Attackers can exploit CVE-2020-12247 to obtain sensitive information from an out-of-bounds read by continuing to use a text-string index after splitting a string into two parts.
Is there any additional information available about CVE-2020-12247?
Yes, you can find additional information about CVE-2020-12247 in the security bulletins on the Foxit Software support page.