CVE-2020-13806: Use After Free
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execution after a deletion or close operation.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.7.2
Foxitsoftware Reader<9.7.2
Remediation
Patch Available
Event History
Jun 4, 2020
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
Description
Frequently Asked Questions
1
What is CVE-2020-13806?
CVE-2020-13806 is a vulnerability found in Foxit Reader and PhantomPDF versions before 9.7.2 that allows for a use-after-free issue.
2
What is the severity of CVE-2020-13806?
The severity of CVE-2020-13806 is high, with a severity score of 7.5.
3
How does CVE-2020-13806 affect Foxitsoftware Phantompdf?
CVE-2020-13806 affects Foxitsoftware Phantompdf versions up to and excluding 9.7.2.
4
How does CVE-2020-13806 affect Foxitsoftware Reader?
CVE-2020-13806 affects Foxitsoftware Reader versions up to and excluding 9.7.2.
5
How can I fix CVE-2020-13806?
To fix CVE-2020-13806, it is recommended to update to the latest version (9.7.2) of Foxit Reader or PhantomPDF.