VYPR
Unrated severityNVD Advisory· Published Jun 4, 2020· Updated Aug 5, 2024

CVE-2019-20817

CVE-2019-20817

Description

An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit Reader and PhantomPDF before version 9.7 are vulnerable to a NULL pointer dereference that may lead to a denial-of-service condition.

Vulnerability

CVE-2019-20817 is a NULL pointer dereference vulnerability in Foxit Reader and PhantomPDF (now Foxit PDF Reader and Foxit PDF Editor) prior to version 9.7 [1]. The bug resides in an unspecified code path that triggers a NULL pointer access when processing a malformed PDF document. No special configuration beyond opening a crafted file is required to reach the vulnerable code.

Exploitation

An attacker can exploit this vulnerability by convincing a user to open a specially crafted PDF file in an affected Foxit Reader or PhantomPDF [1]. No authentication is required, and the attack can be delivered via email, web download, or any other vector that delivers a PDF to the target. Once the user opens the malicious file, the NULL pointer dereference occurs during parsing or rendering.

Impact

Successful exploitation results in a denial of service (application crash) due to the NULL pointer dereference [1]. The vulnerability does not appear to allow code execution; the impact is limited to causing the application to terminate unexpectedly, preventing legitimate use until the application is restarted.

Mitigation

Foxit addressed this issue in Foxit Reader and PhantomPDF version 9.7, released before the publication date of this CVE (2020-06-04) [1]. Users should update to version 9.7 or later to mitigate the vulnerability. No workarounds are documented; upgrading is the recommended action.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.