CVE-2020-11493 Information
Feb 14, 2021
cve
Description
In Foxit Reader and PhantomPDF before 10.0.1 and PhantomPDF before 9.7.3 attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Reference
https://www.foxitsoftware.com/support/security-bulletins.php
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
HIGH
Base Severity
8.1
Share on: