An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.
References
Link | Resource |
---|---|
https://www.foxitsoftware.com/support/security-bulletins.php | Patch Vendor Advisory |
Information
Published : 2019-01-03 15:29
Updated : 2020-08-24 10:37
NVD link : CVE-2019-5005
Mitre link : CVE-2019-5005
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
microsoft
- windows
foxitsoftware
- foxit_reader
- phantompdf