CVE-2018-8036
03.07.2018, 20:29
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
| Vendor | Product | Version |
|---|---|---|
| apache | pdfbox | 1.8.0 < 𝑥 ≤ 1.8.14 |
| apache | pdfbox | 2.0.0 ≤ 𝑥 ≤ 2.0.10 |
| apache | pdfbox | 2.0.0:rc1 |
| apache | pdfbox | 2.0.0:rc2 |
| apache | pdfbox | 2.0.0:rc3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libpdfbox-java |
| ||||||||||||||||||||||||||||||||
| libpdfbox2-java |
|
Common Weakness Enumeration
References