First published: Thu Jan 07 2021(Updated: )
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Code-industry Master Pdf Editor | =5.1.12 | |
Code-industry Master Pdf Editor | =5.1.68 | |
Foxitsoftware Foxit Reader | =9.4 | |
Foxitsoftware Phantompdf | >=9.0<9.4 | |
Foxitsoftware Phantompdf | =8.3.9 | |
Gonitro Nitro Pro | =11.0.3.173 | |
Gonitro Nitro Reader | =5.5.9.2 | |
Iskysoft Pdf Editor 6 | =6.4.2.3521 | |
Iskysoft Pdfelement6 | =6.8.0.3523 | |
Iskysoft Pdfelement6 | =6.8.4.3921 | |
Libreoffice Libreoffice | =6.0.6.2 | |
Libreoffice Libreoffice | =6.1.3.2 | |
Nuance Power PDF Standard | =3.0.0.17 | |
Nuance Power PDF Standard | =3.0.0.30 | |
Nuance Power PDF Standard | =7.0 | |
Qoppa Pdf Studio | =12.0.7 | |
Qoppa Pdf Studio Viewer 2018 | =2018.0.1 | |
Qoppa Pdf Studio Viewer 2018 | =2018.2.0 | |
Soft-xpansion Perfect Pdf 10 | =10.0.0.1 | |
Soft-xpansion Perfect Pdf Reader | =13.0.3 | |
Soft-xpansion Perfect Pdf Reader | =13.1.5 | |
Microsoft Windows | ||
Foxitsoftware Foxit Reader | =9.1.0 | |
Foxitsoftware Foxit Reader | =9.2.0 | |
Linux Linux kernel | ||
Code-industry Master Pdf Editor | =5.1.24 | |
Iskysoft Pdf Editor 6 | =6.6.2.3315 | |
Iskysoft Pdf Editor 6 | =6.7.6.3399 | |
Iskysoft Pdfelement6 | =6.7.1.3355 | |
Iskysoft Pdfelement6 | =6.7.6.3399 | |
Libreoffice Libreoffice | =6.1.0.3 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-18688.
The severity of CVE-2018-18688 is medium with a severity value of 5.3.
The following products are affected by CVE-2018-18688: Code-industry Master Pdf Editor 5.1.12, Code-industry Master Pdf Editor 5.1.68, Foxitsoftware Foxit Reader 9.4, Foxitsoftware Phantompdf (versions between 9.0 and 9.4), Foxitsoftware Phantompdf 8.3.9, Gonitro Nitro Pro 11.0.3.173, Gonitro Nitro Reader 5.5.9.2, Iskysoft Pdf Editor 6.4.2.3521, Iskysoft Pdfelement6 6.8.0.3523, Iskysoft Pdfelement6 6.8.4.3921, Libreoffice Libreoffice 6.0.6.2, Libreoffice Libreoffice 6.1.3.2, Nuance Power PDF Standard 3.0.0.17, Nuance Power PDF Standard 3.0.0.30, Nuance Power PDF Standard 7.0, Qoppa Pdf Studio 12.0.7, Qoppa Pdf Studio Viewer 2018 2018.0.1, Qoppa Pdf Studio Viewer 2018 2018.2.0, Soft-xpansion Perfect Pdf 10.0.0.1, Soft-xpansion Perfect Pdf Reader 13.0.3, Soft-xpansion Perfect Pdf Reader 13.1.5.
CVE-2018-18688 affects PDF software by exploiting an Incremental Saving vulnerability, allowing attackers to add pages or annotations.
No, Microsoft Windows and Linux are not affected by CVE-2018-18688.
To fix the CVE-2018-18688 vulnerability, users should apply the latest security patches and updates provided by the affected software vendors.