CVE-2020-26534

Description

An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.032

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Foxit Reader 10.0.1.35811Windows
Multiple vulnerabilities affected in Foxit PhantomPDF 10 (EXE) 10.0.1.35811Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-334489Foxit Reader (2023.3.0.23028)
PATCH-331212Foxit PhantomPDF 10 (EXE) (10.1.12.37872)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234