CVE-2018-18688
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.
Published:Jan 7, 2021
Last Modified:Nov 21, 2024
EPS:Jan 7, 2021
EPSS Score:0.00004
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Apple
Product
Macos
Apple
Macos
Vendor
Code-industry
Product
Master Pdf Editor
Code-industry
Master Pdf Editor
Vendor
Foxitsoftware
Product
Foxit Reader
Foxitsoftware
Foxit Reader
Vendor
Foxitsoftware
Product
Phantompdf
Foxitsoftware
Phantompdf
Vendor
Gonitro
Product
Nitro Pro
Gonitro
Nitro Pro
Vendor
Gonitro
Product
Nitro Reader
Gonitro
Nitro Reader
Vendor
Iskysoft
Product
Pdf Editor 6
Iskysoft
Pdf Editor 6
Vendor
Iskysoft
Product
Pdfelement6
Iskysoft
Pdfelement6
Vendor
Libreoffice
Product
Libreoffice
Libreoffice
Libreoffice
Vendor
Linux
Product
Linux Kernel
Linux
Linux Kernel
Vendor
Microsoft
Product
Windows
Microsoft
Windows
Vendor
Nuance
Product
Power Pdf Standard
Nuance
Power Pdf Standard
Vendor
Qoppa
Product
Pdf Studio
Qoppa
Pdf Studio
Vendor
Qoppa
Product
Pdf Studio Viewer 2018
Qoppa
Pdf Studio Viewer 2018
Vendor
Soft-xpansion
Product
Perfect Pdf 10
Soft-xpansion
Perfect Pdf 10
Vendor
Soft-xpansion
Product
Perfect Pdf Reader
Soft-xpansion
Perfect Pdf Reader
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
