First published: Fri Oct 02 2020(Updated: )
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V (in the Additional Action and Field dictionaries), a use-after-free can occur with resultant remote code execution (or an information leak).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Foxit Reader | <10.1 | |
Foxitsoftware Phantompdf | <10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-26539.
The severity of CVE-2020-26539 is critical with a severity value of 9.8.
Foxit Reader and PhantomPDF versions before 10.1 are affected by CVE-2020-26539.
CVE-2020-26539 can result in remote code execution or information leak.
Updating to Foxit Reader and PhantomPDF version 10.1 or higher will fix CVE-2020-26539.