CVE Feed

    Dashboard / CVE / CVE-2018-18689

    CVE-2018-18689

    The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.

    Published:Jan 7, 2021
    Last Modified:Nov 27, 2024
    EPS:Jan 7, 2021
    EPSS Score:0.0001
    CVSS Score:5.3

    Affected Products

    Vendor
    Apple
    Product
    Macos
    Vendor
    Avanquest
    Product
    Expert Pdf Ultimate
    Vendor
    Avanquest
    Product
    Pdf Experte Ultimate
    Vendor
    Foxitsoftware
    Product
    Foxit Reader
    Vendor
    Gonitro
    Product
    Nitro Pro
    Vendor
    Gonitro
    Product
    Nitro Reader
    Vendor
    Iskysoft
    Product
    Pdf Editor 6
    Vendor
    Iskysoft
    Product
    Pdfelement6
    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Microsoft
    Product
    Windows
    Vendor
    Pdf-xchange
    Product
    Pdf-xchange Editor
    Vendor
    Pdfforge
    Product
    Pdf Architect
    Vendor
    Qoppa
    Product
    Pdf Studio
    Vendor
    Qoppa
    Product
    Pdf Studio Viewer 2018
    Vendor
    Sodapdf
    Product
    Soda Pdf
    Vendor
    Sodapdf
    Product
    Soda Pdf Desktop
    Vendor
    Soft-xpansion
    Product
    Perfect Pdf 10
    Vendor
    Soft-xpansion
    Product
    Perfect Pdf Reader
    Vendor
    Tracker-software
    Product
    Pdf-xchange Viewer
    Vendor
    Visagesoft
    Product
    Expert Pdf Reader

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High