CVE-2020-13815: High severity foxit phantompdf vulnerability
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indirect object reference.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.7.1
Foxitsoftware Reader<9.7.1
Event History
Jun 4, 2020
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue with Foxit Reader and PhantomPDF?
The vulnerability ID for this issue is CVE-2020-13815.
2
What is the severity of CVE-2020-13815?
The severity of CVE-2020-13815 is high with a value of 7.5.
3
Which software versions are affected by CVE-2020-13815?
Foxit Reader and PhantomPDF versions up to and exclusive of 9.7.1 are affected by CVE-2020-13815.
4
How does CVE-2020-13815 allow stack consumption?
CVE-2020-13815 allows stack consumption through a loop of an indirect object reference.
5
Where can I find more information about CVE-2020-13815?
You can find more information about CVE-2020-13815 in the security bulletins on the Foxit Software website.