CVE-2018-8036

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0.0:rc3:*:*:*:*:*:*

History

21 Nov 2024, 04:13

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2018:2669 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2018:2669 - Third Party Advisory
References () https://lists.apache.org/thread.html/9f62f742fd4fcd81654a9533b8a71349b064250840592bcd502dcfb6%40%3Cusers.pdfbox.apache.org%3E - () https://lists.apache.org/thread.html/9f62f742fd4fcd81654a9533b8a71349b064250840592bcd502dcfb6%40%3Cusers.pdfbox.apache.org%3E -
References () https://lists.apache.org/thread.html/r43491b25b2e5c368c34b106a82eff910a5cea3e90de82ad75cc16540%40%3Cdev.syncope.apache.org%3E - () https://lists.apache.org/thread.html/r43491b25b2e5c368c34b106a82eff910a5cea3e90de82ad75cc16540%40%3Cdev.syncope.apache.org%3E -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6HKVPTJWZGUB4MH4AAOWMRJHRDBYFHGJ/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6HKVPTJWZGUB4MH4AAOWMRJHRDBYFHGJ/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/ -
References () https://www.oracle.com/security-alerts/cpuapr2020.html - () https://www.oracle.com/security-alerts/cpuapr2020.html -

Information

Published : 2018-07-03 20:29

Updated : 2024-11-21 04:13


NVD link : CVE-2018-8036

Mitre link : CVE-2018-8036

CVE.ORG link : CVE-2018-8036


JSON object : View

Products Affected

apache

  • pdfbox
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')