PT-2020-16945 · Foxit · Foxit Reader+1

Published

2020-12-15

·

Updated

2020-12-16

·

CVE-2020-28203

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Foxit Reader versions 10.1.0.37527 and earlier PhantomPDF versions 10.1.0.37527 and earlier
Description An issue was discovered in Foxit Reader and PhantomPDF, where a null pointer access/dereference occurs while opening a crafted PDF file. This leads the application to crash, resulting in a denial of service.
Recommendations For Foxit Reader versions 10.1.0.37527 and earlier, update to a version later than 10.1.0.37527 to resolve the issue. For PhantomPDF versions 10.1.0.37527 and earlier, update to a version later than 10.1.0.37527 to resolve the issue. As a temporary workaround, consider avoiding the use of crafted PDF files to minimize the risk of exploitation.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28203

Affected Products

Foxit Reader
Phantompdf