CVE-2018-11797
published 2018-10-05CVE-2018-11797: In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page…
PriorityP425medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
4.02%
89.4th percentile
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | pdfbox | — | — |
| apache | pdfbox | — | — |
| apache | pdfbox | 1.8.0 – 1.8.15 | — |
| apache | pdfbox | 2.0.1 – 2.0.11 | — |
| apache | tika | — | — |
| apache_software_foundation | apache_pdfbox | — | — |
| apache_software_foundation | apache_pdfbox | — | — |
| debian | libpdfbox-java | < libpdfbox-java 1:1.8.16-1 (bookworm) | libpdfbox-java 1:1.8.16-1 (bookworm) |
| debian | libpdfbox2-java | < libpdfbox-java 1:1.8.16-1 (bookworm) | libpdfbox-java 1:1.8.16-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | retail_xstore_point_of_service | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_apache5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_oracle3.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation
osv·2018-10-17
CVE-2018-11797 [MEDIUM] In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation
In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
GHSA
In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation
ghsa·2018-10-17
CVE-2018-11797 [MEDIUM] CWE-400 In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation
In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
OSV
CVE-2018-11797: In Apache PDFBox 1
osv·2018-10-05·CVSS 5.5
CVE-2018-11797 [MEDIUM] CVE-2018-11797: In Apache PDFBox 1
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Dataloader (Apache pdfbox) — CVE-2018-11797
vendor_oracle·2020-04-15·CVSS 3.1
CVE-2018-11797 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Dataloader (Apache pdfbox) — CVE-2018-11797
Oracle Oracle Retail Applications Risk Matrix: Dataloader (Apache pdfbox) vulnerability
CVE: CVE-2018-11797
CVSS: 3.1
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Red Hat
pdfbox: unbounded computation in parser resulting in a denial of service
vendor_redhat·2018-10-05·CVSS 5.5
CVE-2018-11797 [MEDIUM] CWE-674 pdfbox: unbounded computation in parser resulting in a denial of service
pdfbox: unbounded computation in parser resulting in a denial of service
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Package: pdfbox (Red Hat BPM Suite 6) - Out of support scope
Package: pdfbox (Red Hat JBoss BRMS 6) - Out of support scope
Package: pdfbox (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: pdfbox (Red Hat JBoss Fuse 6) - Out of support scope
Package: pdfbox (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Package: nutch (Red Hat Satellite 5) - Will not fix
Debian
CVE-2018-11797: libpdfbox-java - In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF...
vendor_debian·2018·CVSS 5.5
CVE-2018-11797 [MEDIUM] CVE-2018-11797: libpdfbox-java - In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF...
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Scope: local
bookworm: resolved (fixed in 1:1.8.16-1)
bullseye: resolved (fixed in 1:1.8.16-1)
forky: resolved (fixed in 1:1.8.16-1)
sid: resolved (fixed in 1:1.8.16-1)
trixie: resolved (fixed in 1:1.8.16-1)
Apache
Apache tika: CVE-2018-11797
vendor_apache·CVSS 5.5
CVE-2018-11797 [MEDIUM] Apache tika: CVE-2018-11797
Apache tika: CVE-2018-11797
Very long loop parsing page tree in PDFBox Shawn Rasheed and Jens Dietrich ?-1.19
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11797 pdfbox: unbounded computation in parser resulting in a denial of service [fedora-all]
bugzilla·2018-10-09·CVSS 5.5
CVE-2018-11797 [MEDIUM] CVE-2018-11797 pdfbox: unbounded computation in parser resulting in a denial of service [fedora-all]
CVE-2018-11797 pdfbox: unbounded computation in parser resulting in a denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2018-11797 pdfbox: unbounded computation in parser resulting in a denial of service
bugzilla·2018-10-09·CVSS 5.5
CVE-2018-11797 [MEDIUM] CVE-2018-11797 pdfbox: unbounded computation in parser resulting in a denial of service
CVE-2018-11797 pdfbox: unbounded computation in parser resulting in a denial of service
A vulnerability related to parsing was found in Apache PDFBox parser. A carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
External References:
https://lists.apache.org/thread.html/a9760973a873522f4d4c0a99916ceb74f361d91006b663a0a418d34a@%3Cannounce.apache.org%3E
Discussion:
Created pdfbox tracking bugs for this issue:
Affects: fedora-all [bug 1637494]
---
Regarding the Satellite 5 product:
Reducing the severity to Low : PDFBox is only used to create PDF. No attack vector, where an attacker could send a crafted PDF for parsing, have been found.
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBo
https://lists.apache.org/thread.html/645574bc50b886d39c20b4065d51ccb1cd5d3a6b4750a22edbb565eb%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/a9760973a873522f4d4c0a99916ceb74f361d91006b663a0a418d34a%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r54594251369e14c185da9662a5340a52afbbdf75d61c9c3a69c8f2e8%40%3Cdev.pdfbox.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/10/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6HKVPTJWZGUB4MH4AAOWMRJHRDBYFHGJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://lists.apache.org/thread.html/645574bc50b886d39c20b4065d51ccb1cd5d3a6b4750a22edbb565eb%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/a9760973a873522f4d4c0a99916ceb74f361d91006b663a0a418d34a%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r54594251369e14c185da9662a5340a52afbbdf75d61c9c3a69c8f2e8%40%3Cdev.pdfbox.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/10/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6HKVPTJWZGUB4MH4AAOWMRJHRDBYFHGJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/https://www.oracle.com/security-alerts/cpuapr2020.html
2018-10-05
Published