CVE Vulnerabilities

CVE-2018-11797

Published: Oct 05, 2018 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

Affected Software

Name Vendor Start Version End Version
Pdfbox Apache 1.8.0 (including) 1.8.15 (including)
Pdfbox Apache 2.0.1 (including) 2.0.11 (including)
Pdfbox Apache 2.0-rc1 (including) 2.0-rc1 (including)
Pdfbox Apache 2.0-rc2 (including) 2.0-rc2 (including)
Pdfbox Apache 2.0-rc3 (including) 2.0-rc3 (including)
Pdfbox Apache 2.0.0 (including) 2.0.0 (including)
Red Hat Fuse 7.7.0 RedHat pdfbox *
Libpdfbox-java Ubuntu bionic *
Libpdfbox-java Ubuntu cosmic *
Libpdfbox-java Ubuntu esm-apps/xenial *
Libpdfbox-java Ubuntu trusty *
Libpdfbox-java Ubuntu upstream *
Libpdfbox-java Ubuntu xenial *
Libpdfbox2-java Ubuntu bionic *
Libpdfbox2-java Ubuntu cosmic *
Libpdfbox2-java Ubuntu upstream *

References