CVE-2018-13988: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 3.1% chance of exploitation in the next 30 days.

Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only
  • Freedesktop Poppler: up to and including 0.62.0
  • Red Hat Ansible Tower: version 3.3.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat Openshift Container Platform: version 3.11 only

Published 2018-07-25. Last modified 2026-06-17.