CVE-2021-31811

In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
apachepdfbox
2.0.0 ≤
𝑥
≤ 2.0.23
oraclebanking_corporate_lending_process_management
14.2.0
oraclebanking_corporate_lending_process_management
14.3.0
oraclebanking_corporate_lending_process_management
14.5.0
oraclebanking_credit_facilities_process_management
14.2.0
oraclebanking_credit_facilities_process_management
14.3.0
oraclebanking_credit_facilities_process_management
14.5.0
oraclebanking_supply_chain_finance
14.2.0
oraclebanking_supply_chain_finance
14.3.0
oraclebanking_supply_chain_finance
14.5.0
oraclebanking_trade_finance
14.5
oraclebanking_treasury_management
14.5
oracleflexcube_universal_banking
14.0.0 ≤
𝑥
≤ 14.3.0
oracleflexcube_universal_banking
14.5
oracleoutside_in_technology
8.5.5
oracleprimavera_unifier
17.7 ≤
𝑥
≤ 17.12
oracleprimavera_unifier
18.8
oracleprimavera_unifier
19.12
oracleprimavera_unifier
20.12
oracleretail_customer_management_and_segmentation_foundation
18.1
oraclecommunications_messaging_server
8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libpdfbox-java
bookworm
no-dsa
bullseye
no-dsa
buster
no-dsa
stretch
no-dsa
sid
vulnerable
trixie
vulnerable
libpdfbox2-java
bullseye
no-dsa
buster
no-dsa
bookworm
2.0.27-2
no-dsa
stretch
no-dsa
sid
2.0.29-1
fixed
trixie
2.0.29-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libpdfbox-java
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
dne
libpdfbox2-java
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
bionic
needs-triage
xenial
ignored
trusty
dne
References