CVE-2019-20820
Description
An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference during the parsing of file data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Foxit Reader and PhantomPDF before version 9.7 contain a NULL pointer dereference vulnerability during file parsing, leading to a denial-of-service condition.
Vulnerability
A NULL pointer dereference vulnerability exists in Foxit Reader and Foxit PhantomPDF prior to version 9.7 [1]. The bug occurs during the parsing of file data, where a crafted PDF document can trigger the dereference of a NULL pointer, leading to a crash.
Exploitation
To exploit this vulnerability, an attacker must convince a user to open a specially crafted PDF file using an affected version of Foxit Reader or PhantomPDF [1]. No authentication or special network position is required beyond delivering the file to the victim. The exploitation sequence involves the attacker crafting a malformed PDF that triggers the NULL pointer dereference during the parsing phase.
Impact
Successful exploitation results in a denial-of-service (DoS) condition due to application crash [1]. The impact is limited to availability; there is no evidence of information disclosure or arbitrary code execution in the available references.
Mitigation
The vulnerability is fixed in Foxit Reader and PhantomPDF version 9.7 [1]. Users should update to version 9.7 or later to mitigate the issue. No workarounds are documented in the available references.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Foxit/Reader and PhantomPDFdescription
- Range: <9.7
- Range: <9.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.foxitsoftware.com/support/security-bulletins.phpmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.