CVE-2020-26539: Use After Free
Published Oct 2, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V (in the Additional Action and Field dictionaries), a use-after-free can occur with resultant remote code execution (or an information leak).
Affected Software
2 affected components
Foxitsoftware Foxit Reader<10.1
Foxitsoftware Phantompdf<10.1
Remediation
Event History
Oct 2, 2020
CVE Published
via MITRE·08:01 AM
Data Sourced
via MITRE·08:01 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-26539.
2
What is the severity of CVE-2020-26539?
The severity of CVE-2020-26539 is critical with a severity value of 9.8.
3
What software versions are affected by CVE-2020-26539?
Foxit Reader and PhantomPDF versions before 10.1 are affected by CVE-2020-26539.
4
What is the impact of CVE-2020-26539?
CVE-2020-26539 can result in remote code execution or information leak.
5
Is there a fix for CVE-2020-26539?
Updating to Foxit Reader and PhantomPDF version 10.1 or higher will fix CVE-2020-26539.