CVE-2018-18689
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.
Affected (30)
Products: Avanquest: Expert Pdf Ultimate, Pdf Experte Ultimate · Foxitsoftware: Foxit Reader · Gonitro: Nitro Pro, Nitro Reader · +8 more
Show all products
Avanquest: Expert Pdf Ultimate, Pdf Experte Ultimate · Foxitsoftware: Foxit Reader · Gonitro: Nitro Pro, Nitro Reader · Iskysoft: Pdf Editor 6, Pdfelement6 · Pdf Xchange: Pdf Xchange Editor · Pdfforge: Pdf Architect · Sodapdf: Soda Pdf, Soda Pdf Desktop · Soft Xpansion: Perfect Pdf 10, Perfect Pdf Reader · Tracker Software: Pdf Xchange Viewer · Visagesoft: Expert Pdf Reader · Qoppa: Pdf Studio, Pdf Studio Viewer 2018
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.20 | |
| Version 9.0.270 | |
| Version 9.2.0.9297 | |
| Version 11.0.3.173 | |
| Version 5.5.9.2 | |
| Version 6.4.2.3521 | |
| Version 6.8.0.3523 | |
| Version 7.0.237.1 | |
| Version 6.0.37 | |
| Version 9.3.17 | |
| Version 10.2.09 | |
| Version 10.0.0.1 | |
| Version 13.0.3 | |
| Version 2.5 | |
| Version 9.0.180 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.6.2.3315 | |
| Version 6.7.1.3355 |
| Running on/with | Platform Versions |
|---|---|
Apple Macos | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.1.0 | |
| Version 12.0.7 | |
| Version 2018.0.1 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
References (8)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.