← Back

CVE-2018-18689

nvd nist
Published: Jan 7, 2021Modified: Nov 27, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.

Affected (30)

Show all products
2 products
Expert Pdf Ultimate
Pdf Experte Ultimate
1 product
Foxit Reader
2 products
Nitro Pro
Nitro Reader
2 products
Pdf Editor 6
Pdfelement6
1 product
Pdf Xchange Editor
1 product
Pdf Architect
2 products
Soda Pdf
Soda Pdf Desktop
2 products
Perfect Pdf 10
Perfect Pdf Reader
Pdf Xchange Viewer
1 product
Expert Pdf Reader
2 products
Pdf Studio
Pdf Studio Viewer 2018
Configuration A
21 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 12.0.20
Version 9.0.270
Foxitsoftware
Version 9.2.0.9297
Version 9.3.0.10826
Version 11.0.3.173
Version 5.5.9.2
Version 6.4.2.3521
Iskysoft
Version 6.8.0.3523
Version 6.8.4.3921
Pdf Xchange
Version 7.0.237.1
Version 7.0.326
Pdfforge
Version 6.0.37
Version 6.1.24.1862
Version 9.3.17
Sodapdf
Version 10.2.09
Version 10.2.16.1217
Version 10.0.0.1
Soft Xpansion
Version 13.0.3
Version 13.1.5
Version 2.5
Version 9.0.180
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Iskysoft
Version 6.6.2.3315
Version 6.7.6.3399
Iskysoft
Version 6.7.1.3355
Version 6.7.6.3399
Running on/withPlatform Versions
Apple
Macos
All versions
Configuration C
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Foxitsoftware
Version 9.1.0
Version 9.2.0
Version 12.0.7
Qoppa
Version 2018.0.1
Version 2018.2.0
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (8)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.