Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-18688


The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.


Published

2021-01-07T18:15:12.497

Last Modified

2024-11-21T03:56:22.390

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-347

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application code-industry master_pdf_editor 5.1.12 Yes
Application code-industry master_pdf_editor 5.1.68 Yes
Application foxitsoftware foxit_reader 9.4 Yes
Application foxitsoftware phantompdf < 9.4 Yes
Application foxitsoftware phantompdf 8.3.9 Yes
Application gonitro nitro_pro 11.0.3.173 Yes
Application gonitro nitro_reader 5.5.9.2 Yes
Application iskysoft pdf_editor_6 6.4.2.3521 Yes
Application iskysoft pdfelement6 6.8.0.3523 Yes
Application iskysoft pdfelement6 6.8.4.3921 Yes
Application libreoffice libreoffice 6.0.6.2 Yes
Application libreoffice libreoffice 6.1.3.2 Yes
Application nuance power_pdf_standard 3.0.0.17 Yes
Application nuance power_pdf_standard 3.0.0.30 Yes
Application nuance power_pdf_standard 7.0 Yes
Application qoppa pdf_studio 12.0.7 Yes
Application qoppa pdf_studio_viewer_2018 2018.0.1 Yes
Application qoppa pdf_studio_viewer_2018 2018.2.0 Yes
Application soft-xpansion perfect_pdf_10 10.0.0.1 Yes
Application soft-xpansion perfect_pdf_reader 13.0.3 Yes
Application soft-xpansion perfect_pdf_reader 13.1.5 Yes
Operating System microsoft windows - No
Application code-industry master_pdf_editor 5.1.12 Yes
Application code-industry master_pdf_editor 5.1.68 Yes
Application foxitsoftware foxit_reader 9.1.0 Yes
Application foxitsoftware foxit_reader 9.2.0 Yes
Application libreoffice libreoffice 6.0.6.2 Yes
Application libreoffice libreoffice 6.1.3.2 Yes
Application qoppa pdf_studio 12.0.7 Yes
Application qoppa pdf_studio_viewer_2018 2018.0.1 Yes
Application qoppa pdf_studio_viewer_2018 2018.2.0 Yes
Operating System linux linux_kernel - No
Application code-industry master_pdf_editor 5.1.24 Yes
Application code-industry master_pdf_editor 5.1.68 Yes
Application foxitsoftware foxit_reader 9.1.0 Yes
Application foxitsoftware foxit_reader 9.2.0 Yes
Application iskysoft pdf_editor_6 6.6.2.3315 Yes
Application iskysoft pdf_editor_6 6.7.6.3399 Yes
Application iskysoft pdfelement6 6.7.1.3355 Yes
Application iskysoft pdfelement6 6.7.6.3399 Yes
Application libreoffice libreoffice 6.1.0.3 Yes
Application libreoffice libreoffice 6.1.3.2 Yes
Application qoppa pdf_studio 12.0.7 Yes
Application qoppa pdf_studio_viewer_2018 2018.0.1 Yes
Application qoppa pdf_studio_viewer_2018 2018.2.0 Yes
Operating System apple macos - No

References