CVE-2020-13814: Use After Free
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a dictionary.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.7.1
Foxitsoftware Reader<9.7.1
Event History
Jun 4, 2020
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-13814.
2
What is the severity of CVE-2020-13814?
The severity of CVE-2020-13814 is critical (9.8).
3
Which software versions are affected by CVE-2020-13814?
Foxit Reader and PhantomPDF versions up to (but excluding) 9.7.1 are affected by CVE-2020-13814.
4
What is the description of CVE-2020-13814?
CVE-2020-13814 is a use-after-free vulnerability that occurs via a document lacking a dictionary in Foxit Reader and PhantomPDF.
5
How can I fix CVE-2020-13814?
Updating to Foxit Reader and PhantomPDF version 9.7.1 or later will fix CVE-2020-13814.