CVE-2020-13803: High severity foxit phantompdf mac vulnerability
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypass via a modified file or a file with non-standard signatures.
Affected Software
2 affected components
Foxitsoftware Phantompdf Mac<4.0
Foxitsoftware Reader Mac<4.0
Remediation
Patch Available
Event History
Jun 4, 2020
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-13803.
2
What is the severity of CVE-2020-13803?
The severity of CVE-2020-13803 is high with a severity value of 7.5.
3
What software is affected by CVE-2020-13803?
Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0 are affected by CVE-2020-13803.
4
How does CVE-2020-13803 allow signature validation bypass?
CVE-2020-13803 allows signature validation bypass via a modified file or a file with non-standard signatures.
5
How can I fix CVE-2020-13803?
To fix CVE-2020-13803, update to the latest version (4.0) of Foxit PhantomPDF Mac or Foxit Reader for Mac.