First published: Fri Oct 02 2020(Updated: )
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Foxit Reader | <10.1 | |
Foxitsoftware Phantompdf | <10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-26534 is critical.
Foxit Reader and PhantomPDF versions up to 10.1 are affected by CVE-2020-26534.
To fix CVE-2020-26534, it is recommended to update Foxit Reader and PhantomPDF to version 10.1 or higher.
The CWE ID of CVE-2020-26534 is 416.
More information about CVE-2020-26534 can be found at the following reference: [Foxit Software Security Bulletins](https://www.foxitsoftware.com/support/security-bulletins.html).