VYPR
Unrated severityNVD Advisory· Published Jul 21, 2019· Updated Aug 5, 2024

CVE-2019-14213

CVE-2019-14213

Description

An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the repeated release of the signature dictionary during CSG_SignatureF and CPDF_Document destruction.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit PhantomPDF before 8.3.11 crashes due to double-free of signature dictionary during object destruction.

Vulnerability

An issue exists in Foxit PhantomPDF prior to version 8.3.11 where the application crashes due to a repeated release of the signature dictionary during CSG_SignatureF and CPDF_Document destruction. This double-free condition occurs when the signature dictionary is freed multiple times during object cleanup, leading to memory corruption and a crash. The vulnerability affects all versions of Foxit PhantomPDF before 8.3.11 [1].

Exploitation

An attacker can exploit this vulnerability by crafting a malicious PDF document that includes a specially designed signature dictionary. When a user opens the PDF in an affected version of Foxit PhantomPDF and the document is closed or processed (triggering the destruction of CSG_SignatureF and CPDF_Document objects), the double-free is triggered. No authentication or special privileges are required; the victim only needs to open the file with the vulnerable software.

Impact

Successful exploitation results in a denial of service (DoS) condition, causing the application to crash. There is no indication of code execution or information disclosure in the available references. The crash may lead to loss of unsaved work and disrupt user productivity.

Mitigation

Foxit Software addressed this vulnerability in Foxit PhantomPDF version 8.3.11. Users should update to this version or later to mitigate the issue. No workarounds are documented in the available references [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.