CVE-2020-13809: High severity foxit phantompdf vulnerability
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via long strings in the content stream.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.7.2
Foxitsoftware Reader<9.7.2
Remediation
Patch Available
Event History
Jun 4, 2020
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
Description
Frequently Asked Questions
1
What is CVE-2020-13809?
CVE-2020-13809 is a vulnerability discovered in Foxit Reader and PhantomPDF before 9.7.2 that allows resource consumption via long strings in the content stream.
2
What software versions are affected by CVE-2020-13809?
Foxit Reader and PhantomPDF versions up to exclusive 9.7.2 are affected by CVE-2020-13809.
3
What is the severity of CVE-2020-13809?
CVE-2020-13809 has a severity rating of 7.5, classified as high.
4
How can I fix CVE-2020-13809?
To fix CVE-2020-13809, update Foxit Reader and PhantomPDF to version 9.7.2 or later.
5
Where can I find more information about CVE-2020-13809?
For more information about CVE-2020-13809, you can visit the Foxit Software security bulletins page at https://www.foxitsoftware.com/support/security-bulletins.php.