CVE-2020-26534: Use After Free
Published Oct 2, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
Affected Software
2 affected components
Foxitsoftware Foxit Reader<10.1
Foxitsoftware Phantompdf<10.1
Remediation
Event History
Oct 2, 2020
CVE Published
via MITRE·08:02 AM
Data Sourced
via MITRE·08:02 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-26534?
The severity of CVE-2020-26534 is critical.
2
What software is affected by CVE-2020-26534?
Foxit Reader and PhantomPDF versions up to 10.1 are affected by CVE-2020-26534.
3
How can I fix CVE-2020-26534?
To fix CVE-2020-26534, it is recommended to update Foxit Reader and PhantomPDF to version 10.1 or higher.
4
What is the CWE ID of CVE-2020-26534?
The CWE ID of CVE-2020-26534 is 416.
5
Where can I find more information about CVE-2020-26534?
More information about CVE-2020-26534 can be found at the following reference: [Foxit Software Security Bulletins](https://www.foxitsoftware.com/support/security-bulletins.html).