MEDIUM · 5.3

CVE-2018-18689

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exist...

Vulnerability Description

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AvanquestExpert Pdf Ultimate12.0.20
AvanquestPdf Experte Ultimate9.0.270
FoxitsoftwareFoxit Reader9.1.0
GonitroNitro Pro11.0.3.173
GonitroNitro Reader5.5.9.2
IskysoftPdf Editor 66.4.2.3521
IskysoftPdfelement66.8.0.3523
Pdf-XchangePdf-Xchange Editor7.0.237.1
PdfforgePdf Architect6.0.37
QoppaPdf Studio12.0.7
QoppaPdf Studio Viewer 20182018.0.1
SodapdfSoda Pdf9.3.17
SodapdfSoda Pdf Desktop10.2.09
Soft-XpansionPerfect Pdf 1010.0.0.1
Soft-XpansionPerfect Pdf Reader13.0.3
Tracker-SoftwarePdf-Xchange Viewer2.5
VisagesoftExpert Pdf Reader9.0.180
MicrosoftWindows-
AppleMacos-
LinuxLinux Kernel-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-18689?

CVE-2018-18689 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exist...

How severe is CVE-2018-18689?

CVE-2018-18689 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-18689?

Check the references section above for vendor advisories and patch information. Affected products include: Avanquest Expert Pdf Ultimate, Avanquest Pdf Experte Ultimate, Foxitsoftware Foxit Reader, Gonitro Nitro Pro, Gonitro Nitro Reader.