CVE-2020-11493
Severity CVSS v4.0:
Pending analysis
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
04/09/2020
Last modified:
09/09/2020
Description
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* | 9.7.2.29539 (including) | |
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* | 10.0.0.35798 (including) | |
cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:* | 10.0.0.35798 (including) | |
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page