Vulnerability Description
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freedesktop | Poppler | <= 0.62.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Debian | Debian Linux | 8.0 |
| Redhat | Ansible Tower | 3.3.0 |
| Redhat | Openshift Container Platform | 3.11 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/148661/PDFunite-0.62.0-Buffer-Overflow.htmlThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3140Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=CVE-2018-13988Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1602838Issue TrackingThird Party Advisory
- https://cgit.freedesktop.org/poppler/poppler/commit/?id=004e3c10df0abda214f0c293PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00024.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3757-1/Third Party Advisory
- http://packetstormsecurity.com/files/148661/PDFunite-0.62.0-Buffer-Overflow.htmlThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3140Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=CVE-2018-13988Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1602838Issue TrackingThird Party Advisory
FAQ
What is CVE-2018-13988?
CVE-2018-13988 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corru...
How severe is CVE-2018-13988?
CVE-2018-13988 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-13988?
Check the references section above for vendor advisories and patch information. Affected products include: Freedesktop Poppler, Canonical Ubuntu Linux, Debian Debian Linux, Redhat Ansible Tower, Redhat Openshift Container Platform.