CVE-2018-18688

Source
https://cve.org/CVERecord?id=CVE-2018-18688
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-18688.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-18688
Published
2021-01-07T18:15:12.497Z
Modified
2026-04-10T04:07:18.414158Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.

References

Affected packages

Git / github.com/libreoffice/core

Affected ranges

Type
GIT
Repo
https://github.com/libreoffice/core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "5.1.12"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.0.6.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.1.3.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "5.1.12"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.0.6.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.1.3.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "5.1.24"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.1.0.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.1.3.2"
        }
    ]
}

Affected versions

Other
MELD_LIBREOFFICE_REPOS
libreoffice-3-5-branch-point
libreoffice-3-6-branch-point
libreoffice-4-0-branch-point
libreoffice-4-1-branch-point
libreoffice-4-2-branch-point
libreoffice-4-2-milestone-1
libreoffice-4-3-branch-point
libreoffice-4-4-branch-point
libreoffice-5-0-branch-point
libreoffice-5-1-branch-point
libreoffice-5-2-branch-point
libreoffice-5-3-branch-point
libreoffice-5-4-branch-point
libreoffice-6-0-branch-point
libreoffice-6-1-branch-point
libreoffice-6-2-branch-point
libreoffice-6-3-branch-point
libreoffice-6-4-branch-point
libreoffice-7-0-branch-point
mimo-7-0-branch-point
windows_build_successful_2011_11_08
cp-5.*
cp-5.1-1
cp-5.1-10
cp-5.1-11
cp-5.1-12
cp-5.1-13
cp-5.1-14
cp-5.1-15
cp-5.1-16
cp-5.1-17
cp-5.1-18
cp-5.1-2
cp-5.1-20
cp-5.1-21
cp-5.1-22
cp-5.1-23
cp-5.1-24
cp-5.1-3
cp-5.1-4
cp-5.1-5
cp-5.1-6
cp-5.1-7
cp-5.1-8
cp-5.1-9
cp-5.1-branch-point
cp-6.*
cp-6.0-branch-point
gpg4libre-review-5.*
gpg4libre-review-5.4.99
libreoffice-3.*
libreoffice-3.5.0.0
libreoffice-5.*
libreoffice-5.1.0.0.beta2
libreoffice-6.*
libreoffice-6.0.6.2
libreoffice-6.1.0.3
libreoffice-6.1.3.2
sdremote-2.*
sdremote-2.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-18688.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "5.1.68"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.4"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "9.0"
            },
            {
                "fixed": "9.4"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "8.3.9"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "11.0.3.173"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "5.5.9.2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.4.2.3521"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.8.0.3523"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.8.4.3921"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "3.0.0.17"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "3.0.0.30"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.0.7"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2018.0.1"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2018.2.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.0.0.1"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "13.0.3"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "13.1.5"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "5.1.68"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.1.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.2.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.0.7"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2018.0.1"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2018.2.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "5.1.68"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.1.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.2.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.6.2.3315"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.7.6.3399"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.7.1.3355"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.7.6.3399"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.0.7"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2018.0.1"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2018.2.0"
            }
        ]
    }
]