5.3

CVE-2018-18688

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.

Data is provided by the National Vulnerability Database (NVD)
Code-industryMaster Pdf Editor Version5.1.12
   MicrosoftWindows Version-
Code-industryMaster Pdf Editor Version5.1.68
   MicrosoftWindows Version-
FoxitsoftwareFoxit Reader Version9.4
   MicrosoftWindows Version-
FoxitsoftwarePhantompdf Version >= 9.0 < 9.4
   MicrosoftWindows Version-
FoxitsoftwarePhantompdf Version8.3.9
   MicrosoftWindows Version-
GonitroNitro Pro Version11.0.3.173
   MicrosoftWindows Version-
GonitroNitro Reader Version5.5.9.2
   MicrosoftWindows Version-
IskysoftPdf Editor 6 Version6.4.2.3521 SwEditionprofessional
   MicrosoftWindows Version-
IskysoftPdfelement6 Version6.8.0.3523 SwEditionprofessional
   MicrosoftWindows Version-
IskysoftPdfelement6 Version6.8.4.3921 SwEditionprofessional
   MicrosoftWindows Version-
LibreofficeLibreoffice Version6.0.6.2
   MicrosoftWindows Version-
LibreofficeLibreoffice Version6.1.3.2
   MicrosoftWindows Version-
NuancePower Pdf Standard Version3.0.0.17
   MicrosoftWindows Version-
NuancePower Pdf Standard Version3.0.0.30
   MicrosoftWindows Version-
NuancePower Pdf Standard Version7.0
   MicrosoftWindows Version-
QoppaPdf Studio Version12.0.7 SwEditionprofessional
   MicrosoftWindows Version-
QoppaPdf Studio Viewer 2018 Version2018.0.1
   MicrosoftWindows Version-
QoppaPdf Studio Viewer 2018 Version2018.2.0
   MicrosoftWindows Version-
Soft-xpansionPerfect Pdf 10 Version10.0.0.1 SwEditionpremium
   MicrosoftWindows Version-
Soft-xpansionPerfect Pdf Reader Version13.0.3
   MicrosoftWindows Version-
Soft-xpansionPerfect Pdf Reader Version13.1.5
   MicrosoftWindows Version-
Code-industryMaster Pdf Editor Version5.1.12
   LinuxLinux Kernel Version-
Code-industryMaster Pdf Editor Version5.1.68
   LinuxLinux Kernel Version-
FoxitsoftwareFoxit Reader Version9.1.0
   LinuxLinux Kernel Version-
FoxitsoftwareFoxit Reader Version9.2.0
   LinuxLinux Kernel Version-
LibreofficeLibreoffice Version6.0.6.2
   LinuxLinux Kernel Version-
LibreofficeLibreoffice Version6.1.3.2
   LinuxLinux Kernel Version-
QoppaPdf Studio Version12.0.7 SwEditionprofessional
   LinuxLinux Kernel Version-
QoppaPdf Studio Viewer 2018 Version2018.0.1
   LinuxLinux Kernel Version-
QoppaPdf Studio Viewer 2018 Version2018.2.0
   LinuxLinux Kernel Version-
Code-industryMaster Pdf Editor Version5.1.24
   ApplemacOS Version-
Code-industryMaster Pdf Editor Version5.1.68
   ApplemacOS Version-
FoxitsoftwareFoxit Reader Version9.1.0
   ApplemacOS Version-
FoxitsoftwareFoxit Reader Version9.2.0
   ApplemacOS Version-
IskysoftPdf Editor 6 Version6.6.2.3315 SwEditionprofessional
   ApplemacOS Version-
IskysoftPdf Editor 6 Version6.7.6.3399 SwEditionprofessional
   ApplemacOS Version-
IskysoftPdfelement6 Version6.7.1.3355 SwEditionprofessional
   ApplemacOS Version-
IskysoftPdfelement6 Version6.7.6.3399 SwEditionprofessional
   ApplemacOS Version-
LibreofficeLibreoffice Version6.1.0.3
   ApplemacOS Version-
LibreofficeLibreoffice Version6.1.3.2
   ApplemacOS Version-
QoppaPdf Studio Version12.0.7 SwEditionprofessional
   ApplemacOS Version-
QoppaPdf Studio Viewer 2018 Version2018.0.1
   ApplemacOS Version-
QoppaPdf Studio Viewer 2018 Version2018.2.0
   ApplemacOS Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0% 0.002
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.