CVE Vulnerabilities

CVE-2018-18689

Improper Verification of Cryptographic Signature

Published: Jan 07, 2021 | Modified: Jan 15, 2021
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Expert_pdf_ultimate Avanquest 12.0.20 (including) 12.0.20 (including)
Pdf_experte_ultimate Avanquest 9.0.270 (including) 9.0.270 (including)
Foxit_reader Foxitsoftware 9.1.0 (including) 9.1.0 (including)
Foxit_reader Foxitsoftware 9.2.0.9297 (including) 9.2.0.9297 (including)
Foxit_reader Foxitsoftware 9.3.0.10826 (including) 9.3.0.10826 (including)
Nitro_pro Gonitro 11.0.3.173 (including) 11.0.3.173 (including)
Nitro_reader Gonitro 5.5.9.2 (including) 5.5.9.2 (including)
Pdf_editor_6 Iskysoft 6.4.2.3521 (including) 6.4.2.3521 (including)
Pdfelement6 Iskysoft 6.8.0.3523 (including) 6.8.0.3523 (including)
Pdfelement6 Iskysoft 6.8.4.3921 (including) 6.8.4.3921 (including)
Pdf_architect Pdfforge 6.0.37 (including) 6.0.37 (including)
Pdf_architect Pdfforge 6.1.24.1862 (including) 6.1.24.1862 (including)
Pdf_studio Qoppa 12.0.7 (including) 12.0.7 (including)
Pdf_studio_viewer_2018 Qoppa 2018.0.1 (including) 2018.0.1 (including)
Pdf_studio_viewer_2018 Qoppa 2018.2.0 (including) 2018.2.0 (including)
Soda_pdf Sodapdf 9.3.17 (including) 9.3.17 (including)
Soda_pdf_desktop Sodapdf 10.2.09 (including) 10.2.09 (including)
Soda_pdf_desktop Sodapdf 10.2.16.1217 (including) 10.2.16.1217 (including)
Perfect_pdf_10 Soft-xpansion 10.0.0.1 (including) 10.0.0.1 (including)
Perfect_pdf_reader Soft-xpansion 13.0.3 (including) 13.0.3 (including)
Perfect_pdf_reader Soft-xpansion 13.1.5 (including) 13.1.5 (including)
Pdf-xchange_editor Tracker-software 7.0.237.1 (including) 7.0.237.1 (including)
Pdf-xchange_editor Tracker-software 7.0.326 (including) 7.0.326 (including)
Pdf-xchange_viewer Tracker-software 2.5 (including) 2.5 (including)
Expert_pdf_reader Visagesoft 9.0.180 (including) 9.0.180 (including)

References