HIGH · 8.1

CVE-2020-11493

In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to ...

Vulnerability Description

In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
FoxitsoftwarePhantompdf<= 9.7.2.29539
MicrosoftWindows-
FoxitsoftwareReader<= 10.0.0.35798

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11493?

CVE-2020-11493 is a vulnerability with a CVSS score of 8.1 (HIGH). In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to ...

How severe is CVE-2020-11493?

CVE-2020-11493 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11493?

Check the references section above for vendor advisories and patch information. Affected products include: Foxitsoftware Phantompdf, Microsoft Windows, Foxitsoftware Reader.