5.3

CVE-2018-18689

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Avanquest ≫ Expert Pdf Ultimate Version 12.0.20
   Microsoft ≫ Windows Version -
Avanquest ≫ Pdf Experte Ultimate Version 9.0.270
   Microsoft ≫ Windows Version -
Foxitsoftware ≫ Foxit Reader Version 9.1.0
   Microsoft ≫ Windows Version -
Foxitsoftware ≫ Foxit Reader Version 9.2.0.9297
   Microsoft ≫ Windows Version -
Foxitsoftware ≫ Foxit Reader Version 9.3.0.10826
   Microsoft ≫ Windows Version -
Gonitro ≫ Nitro Pro Version 11.0.3.173
   Microsoft ≫ Windows Version -
Gonitro ≫ Nitro Reader Version 5.5.9.2
   Microsoft ≫ Windows Version -
Iskysoft ≫ Pdf Editor 6 Version 6.4.2.3521 SwEdition professional
   Microsoft ≫ Windows Version -
Iskysoft ≫ Pdfelement6 Version 6.8.0.3523 SwEdition professional
   Microsoft ≫ Windows Version -
Iskysoft ≫ Pdfelement6 Version 6.8.4.3921 SwEdition professional
   Microsoft ≫ Windows Version -
Pdf-xchange ≫ Pdf-xchange Editor Version 7.0.237.1
   Microsoft ≫ Windows Version -
Pdf-xchange ≫ Pdf-xchange Editor Version 7.0.326
   Microsoft ≫ Windows Version -
Pdfforge ≫ Pdf Architect Version 6.0.37
   Microsoft ≫ Windows Version -
Pdfforge ≫ Pdf Architect Version 6.1.24.1862
   Microsoft ≫ Windows Version -
Qoppa ≫ Pdf Studio Version 12.0.7 SwEdition professional
   Microsoft ≫ Windows Version -
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.0.1
   Microsoft ≫ Windows Version -
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.2.0
   Microsoft ≫ Windows Version -
Sodapdf ≫ Soda Pdf Version 9.3.17
   Microsoft ≫ Windows Version -
Sodapdf ≫ Soda Pdf Desktop Version 10.2.09
   Microsoft ≫ Windows Version -
Sodapdf ≫ Soda Pdf Desktop Version 10.2.16.1217
   Microsoft ≫ Windows Version -
Soft-xpansion ≫ Perfect Pdf 10 Version 10.0.0.1 SwEdition premium
   Microsoft ≫ Windows Version -
Soft-xpansion ≫ Perfect Pdf Reader Version 13.0.3
   Microsoft ≫ Windows Version -
Soft-xpansion ≫ Perfect Pdf Reader Version 13.1.5
   Microsoft ≫ Windows Version -
Tracker-software ≫ Pdf-xchange Viewer Version 2.5
   Microsoft ≫ Windows Version -
Visagesoft ≫ Expert Pdf Reader Version 9.0.180
   Microsoft ≫ Windows Version -
Foxitsoftware ≫ Foxit Reader Version 9.1.0
   Apple ≫ macOS Version -
Foxitsoftware ≫ Foxit Reader Version 9.2.0
   Apple ≫ macOS Version -
Iskysoft ≫ Pdf Editor 6 Version 6.6.2.3315 SwEdition professional
   Apple ≫ macOS Version -
Iskysoft ≫ Pdf Editor 6 Version 6.7.6.3399 SwEdition professional
   Apple ≫ macOS Version -
Iskysoft ≫ Pdfelement6 Version 6.7.1.3355 SwEdition professional
   Apple ≫ macOS Version -
Iskysoft ≫ Pdfelement6 Version 6.7.6.3399 SwEdition professional
   Apple ≫ macOS Version -
Qoppa ≫ Pdf Studio Version 12.0.7 SwEdition professional
   Apple ≫ macOS Version -
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.0.1
   Apple ≫ macOS Version -
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.2.0
   Apple ≫ macOS Version -
Foxitsoftware ≫ Foxit Reader Version 9.1.0
   Linux ≫ Linux Kernel Version -
Foxitsoftware ≫ Foxit Reader Version 9.2.0
   Linux ≫ Linux Kernel Version -
Qoppa ≫ Pdf Studio Version 12.0.7 SwEdition professional
   Linux ≫ Linux Kernel Version -
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.0.1
   Linux ≫ Linux Kernel Version -
Qoppa ≫ Pdf Studio Viewer 2018 Version 2018.2.0
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.69% 0.883
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

https://www.foxitsoftware.com/support/security-bulletins.php
Vendor Advisory
https://pdf-insecurity.org/signature/evaluation_2018.html
Third Party Advisory
https://pdf-insecurity.org/signature/signature.html
Third Party Advisory
https://www.pdfa.org/recently-identified-pdf-digital-signature-vulnerabilities/
Third Party Advisory