← Back

CVE-2019-5005

nvd nist
Published: Jan 3, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.

Affected (2)

2 products
Foxit Reader
Phantompdf
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 9.4
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.4
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (2)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.