VYPR
Unrated severityNVD Advisory· Published Jun 4, 2020· Updated Aug 5, 2024

CVE-2019-20820

CVE-2019-20820

Description

An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference during the parsing of file data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit Reader and PhantomPDF before version 9.7 contain a NULL pointer dereference vulnerability during file parsing, leading to a denial-of-service condition.

Vulnerability

A NULL pointer dereference vulnerability exists in Foxit Reader and Foxit PhantomPDF prior to version 9.7 [1]. The bug occurs during the parsing of file data, where a crafted PDF document can trigger the dereference of a NULL pointer, leading to a crash.

Exploitation

To exploit this vulnerability, an attacker must convince a user to open a specially crafted PDF file using an affected version of Foxit Reader or PhantomPDF [1]. No authentication or special network position is required beyond delivering the file to the victim. The exploitation sequence involves the attacker crafting a malformed PDF that triggers the NULL pointer dereference during the parsing phase.

Impact

Successful exploitation results in a denial-of-service (DoS) condition due to application crash [1]. The impact is limited to availability; there is no evidence of information disclosure or arbitrary code execution in the available references.

Mitigation

The vulnerability is fixed in Foxit Reader and PhantomPDF version 9.7 [1]. Users should update to version 9.7 or later to mitigate the issue. No workarounds are documented in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.