CVE-2020-26537: Critical severity foxit reader vulnerability
Published Oct 2, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number of color components in a color space. This causes an out-of-bounds write.
Affected Software
2 affected components
Foxitsoftware Foxit Reader<10.1
Foxitsoftware Phantompdf<10.1
Remediation
Event History
Oct 2, 2020
CVE Published
via MITRE·08:01 AM
Data Sourced
via MITRE·08:01 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-26537.
2
What is the severity rating of CVE-2020-26537?
CVE-2020-26537 has a severity rating of 9.8, which is classified as critical.
3
What software is affected by CVE-2020-26537?
Foxit Reader and PhantomPDF versions before 10.1 are affected by CVE-2020-26537.
4
What is the impact of CVE-2020-26537?
CVE-2020-26537 allows an attacker to perform an out-of-bounds write, potentially leading to arbitrary code execution.
5
Where can I find more information about CVE-2020-26537?
More information about CVE-2020-26537 can be found at the following link: https://www.foxitsoftware.com/support/security-bulletins.html