CVE-2018-11797

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
apachepdfbox
1.8.0 ≤
𝑥
≤ 1.8.15
apachepdfbox
2.0.1 ≤
𝑥
≤ 2.0.11
apachepdfbox
2.0:rc1
apachepdfbox
2.0:rc2
apachepdfbox
2.0:rc3
apachepdfbox
2.0.0
oracleretail_xstore_point_of_service
17.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libpdfbox-java
bookworm
1:1.8.16-2
fixed
bullseye
1:1.8.16-2
fixed
stretch
no-dsa
sid
1:1.8.16-5
fixed
trixie
1:1.8.16-5
fixed
libpdfbox2-java
bullseye
2.0.23-1
fixed
stretch
no-dsa
bookworm
2.0.27-2
fixed
sid
2.0.29-1
fixed
trixie
2.0.29-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libpdfbox-java
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
Fixed 1:1.8.16-2~18.04
released
bionic
Fixed 1:1.8.16-2~18.04
released
xenial
needed
trusty
dne
libpdfbox2-java
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
Fixed 2.0.13-2~18.04
released
bionic
Fixed 2.0.13-2~18.04
released
xenial
dne
trusty
dne
References