CVE Vulnerabilities

CVE-2018-16042

Improper Verification of Cryptographic Signature

Published: Jan 18, 2019 | Modified: Jan 14, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a security bypass vulnerability. Successful exploitation could lead to information disclosure.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Acrobat_dc Adobe 15.006.30060 (including) 15.006.30457 (including)
Acrobat_dc Adobe 15.008.20082 (including) 19.008.20081 (including)
Acrobat_dc Adobe 17.011.30056 (including) 17.011.30106 (including)
Acrobat_reader_dc Adobe 15.006.30060 (including) 15.006.30457 (including)
Acrobat_reader_dc Adobe 15.008.20082 (including) 19.008.20081 (including)
Acrobat_reader_dc Adobe 17.011.30059 (including) 17.011.30106 (including)
Reader Adobe 11.0.10 (including) 11.0.10 (including)
Reader Adobe 11.0.23 (including) 11.0.23 (including)
Pdf_editor_6 Iskysoft 6.4.2.3521 (including) 6.4.2.3521 (including)
Pdfelement6 Iskysoft 6.8.0.3523 (including) 6.8.0.3523 (including)
Pdfelement6 Iskysoft 6.8.4.3921 (including) 6.8.4.3921 (including)

References