Severity
5.5MEDIUM
EPSS
1.6%
top 18.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 5
Latest updateApr 15

Description

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

Mavenorg.apache.pdfbox:pdfbox1.8.01.8.16+1
NVDapache/pdfbox1.8.01.8.15+3
CVEListV5apache_software_foundation/apache_pdfbox1.8.0 to 1.8.15, 2.0.0RC1 to 2.0.11+1
Debianlibpdfbox-java< 1:1.8.16-1+3
Debianlibpdfbox2-java< 2.0.12-1+3

Also affects: Fedora 29, 30

Patches

🔴Vulnerability Details

4
OSV
In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation2018-10-17
GHSA
In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation2018-10-17
OSV
CVE-2018-11797: In Apache PDFBox 12018-10-05
CVEList
CVE-2018-11797: In Apache PDFBox 12018-10-05

📋Vendor Advisories

4
Oracle
Oracle Oracle Retail Applications Risk Matrix: Dataloader (Apache pdfbox) — CVE-2018-117972020-04-15
Red Hat
pdfbox: unbounded computation in parser resulting in a denial of service2018-10-05
Debian
CVE-2018-11797: libpdfbox-java - In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF...2018
Apache
Apache tika: CVE-2018-11797

💬Community

2
Bugzilla
CVE-2018-11797 pdfbox: unbounded computation in parser resulting in a denial of service [fedora-all]2018-10-09
Bugzilla
CVE-2018-11797 pdfbox: unbounded computation in parser resulting in a denial of service2018-10-09
CVE-2018-11797 (MEDIUM CVSS 5.5) | In Apache PDFBox 1.8.0 to 1.8.15 an | cvebase.io