5.3
CVE-2018-18688
- EPSS 1.13%
- Veröffentlicht 07.01.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 03:56:22
- Erkennungen
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Code-industry ≫ Master Pdf Editor Version 5.1.12
Code-industry ≫ Master Pdf Editor Version 5.1.68
Foxitsoftware ≫ Foxit Reader Version 9.4
Foxitsoftware ≫ Phantompdf Version >= 9.0 < 9.4
Foxitsoftware ≫ Phantompdf Version 8.3.9
Gonitro ≫ Nitro Reader Version 5.5.9.2
Iskysoft ≫ Pdf Editor 6 Version 6.4.2.3521 SwEdition professional
Iskysoft ≫ Pdfelement6 Version 6.8.0.3523 SwEdition professional
Iskysoft ≫ Pdfelement6 Version 6.8.4.3921 SwEdition professional
Libreoffice ≫ Libreoffice Version 6.0.6.2
Libreoffice ≫ Libreoffice Version 6.1.3.2
Nuance ≫ Power Pdf Standard Version 3.0.0.17
Nuance ≫ Power Pdf Standard Version 3.0.0.30
Nuance ≫ Power Pdf Standard Version 7.0
Qoppa ≫ Pdf Studio Version 12.0.7 SwEdition professional
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.0.1
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.2.0
Soft-xpansion ≫ Perfect Pdf 10 Version 10.0.0.1 SwEdition premium
Soft-xpansion ≫ Perfect Pdf Reader Version 13.0.3
Soft-xpansion ≫ Perfect Pdf Reader Version 13.1.5
Code-industry ≫ Master Pdf Editor Version 5.1.12
Code-industry ≫ Master Pdf Editor Version 5.1.68
Foxitsoftware ≫ Foxit Reader Version 9.1.0
Foxitsoftware ≫ Foxit Reader Version 9.2.0
Libreoffice ≫ Libreoffice Version 6.0.6.2
Libreoffice ≫ Libreoffice Version 6.1.3.2
Qoppa ≫ Pdf Studio Version 12.0.7 SwEdition professional
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.0.1
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.2.0
Code-industry ≫ Master Pdf Editor Version 5.1.24
Code-industry ≫ Master Pdf Editor Version 5.1.68
Foxitsoftware ≫ Foxit Reader Version 9.1.0
Foxitsoftware ≫ Foxit Reader Version 9.2.0
Iskysoft ≫ Pdf Editor 6 Version 6.6.2.3315 SwEdition professional
Iskysoft ≫ Pdf Editor 6 Version 6.7.6.3399 SwEdition professional
Iskysoft ≫ Pdfelement6 Version 6.7.1.3355 SwEdition professional
Iskysoft ≫ Pdfelement6 Version 6.7.6.3399 SwEdition professional
Libreoffice ≫ Libreoffice Version 6.1.0.3
Libreoffice ≫ Libreoffice Version 6.1.3.2
Qoppa ≫ Pdf Studio Version 12.0.7 SwEdition professional
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.0.1
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.13% | 0.622 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
https://www.foxitsoftware.com/support/security-bulletins.php
https://pdf-insecurity.org/signature/evaluation_2018.html
https://pdf-insecurity.org/signature/signature.html
https://www.pdfa.org/recently-identified-pdf-digital-signature-vulnerabilities/