CVE Vulnerabilities

CVE-2018-16042

Improper Verification of Cryptographic Signature

Published: Jan 18, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a security bypass vulnerability. Successful exploitation could lead to information disclosure.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
Acrobat_dcAdobe15.006.30060 (including)15.006.30457 (including)
Acrobat_dcAdobe15.008.20082 (including)19.008.20081 (including)
Acrobat_dcAdobe17.011.30056 (including)17.011.30106 (including)
Acrobat_reader_dcAdobe15.006.30060 (including)15.006.30457 (including)
Acrobat_reader_dcAdobe15.008.20082 (including)19.008.20081 (including)
Acrobat_reader_dcAdobe17.011.30059 (including)17.011.30106 (including)
ReaderAdobe11.0.10 (including)11.0.10 (including)
ReaderAdobe11.0.23 (including)11.0.23 (including)
Pdf_editor_6Iskysoft6.4.2.3521 (including)6.4.2.3521 (including)
Pdfelement6Iskysoft6.8.0.3523 (including)6.8.0.3523 (including)
Pdfelement6Iskysoft6.8.4.3921 (including)6.8.4.3921 (including)

References