CVE-2021-31812
published 2021-06-12CVE-2021-31812: In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior…
PriorityP426medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
3.05%
86.1th percentile
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | pdfbox | 2.0.0 – 2.0.23 | — |
| apache | tika | — | — |
| apache_software_foundation | apache_pdfbox | >= Apache PDFBox < 2.0.24 | 2.0.24 |
| debian | libpdfbox-java | < libpdfbox2-java 2.0.24-1 (bookworm) | libpdfbox2-java 2.0.24-1 (bookworm) |
| debian | libpdfbox2-java | < libpdfbox2-java 2.0.24-1 (bookworm) | libpdfbox2-java 2.0.24-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | retail_customer_management_and_segmentation_foundation | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_apache5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache PDFBox) — CVE-2021-31812
vendor_oracle·2023-01-15·CVSS 5.5
CVE-2021-31812 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache PDFBox) — CVE-2021-31812
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache PDFBox) vulnerability
CVE: CVE-2021-31812
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Smart Answer (Apache PDFBox) — CVE-2021-31812
vendor_oracle·2022-07-15·CVSS 5.5
CVE-2021-31812 [MEDIUM] Oracle Oracle Siebel CRM Risk Matrix: Smart Answer (Apache PDFBox) — CVE-2021-31812
Oracle Oracle Siebel CRM Risk Matrix: Smart Answer (Apache PDFBox) vulnerability
CVE: CVE-2021-31812
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache PDFBox) — CVE-2021-31812
vendor_oracle·2022-04-15·CVSS 5.5
CVE-2021-31812 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache PDFBox) — CVE-2021-31812
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache PDFBox) vulnerability
CVE: CVE-2021-31812
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Retail Applications Risk Matrix: Security (Apache PDFbox) — CVE-2021-31812
vendor_oracle·2022-01-15·CVSS 5.5
CVE-2021-31812 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Security (Apache PDFbox) — CVE-2021-31812
Oracle Oracle Retail Applications Risk Matrix: Security (Apache PDFbox) vulnerability
CVE: CVE-2021-31812
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Monitoring (Apache PDFBox) — CVE-2021-31812
vendor_oracle·2021-10-15·CVSS 5.5
CVE-2021-31812 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Monitoring (Apache PDFBox) — CVE-2021-31812
Oracle Oracle Communications Applications Risk Matrix: Monitoring (Apache PDFBox) vulnerability
CVE: CVE-2021-31812
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
Red Hat
pdfbox: infinite loop while loading a crafted PDF file
vendor_redhat·2021-06-12·CVSS 5.5
CVE-2021-31812 [MEDIUM] CWE-835 pdfbox: infinite loop while loading a crafted PDF file
pdfbox: infinite loop while loading a crafted PDF file
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
Package: pdfbox (Red Hat BPM Suite 6) - Out of support scope
Package: pdfbox (Red Hat Fuse 7) - Fix deferred
Package: pdfbox (Red Hat Integration Camel K 1) - Affected
Package: pdfbox (Red Hat JBoss BRMS 6) - Out of support scope
Package: pdfbox (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: pdfbox (Red Hat JBoss Fuse 6) - Out of support scope
Package: pdfbox (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Debian
CVE-2021-31812: libpdfbox-java - In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop whil...
vendor_debian·2021·CVSS 5.5
CVE-2021-31812 [MEDIUM] CVE-2021-31812: libpdfbox-java - In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop whil...
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Apache
Apache tika: CVE-2021-31812
vendor_apache·CVSS 5.5
CVE-2021-31812 [MEDIUM] Apache tika: CVE-2021-31812
Apache tika: CVE-2021-31812
Infinite loop when loading a crafted PDF in PDFBox before 2.0.24 Chaoyuan Peng ?-1.26
GHSA
Infinite Loop in Apache PDFBox
ghsa·2021-06-15
CVE-2021-31812 [MEDIUM] CWE-834 Infinite Loop in Apache PDFBox
Infinite Loop in Apache PDFBox
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
OSV
Infinite Loop in Apache PDFBox
osv·2021-06-15
CVE-2021-31812 [MEDIUM] Infinite Loop in Apache PDFBox
Infinite Loop in Apache PDFBox
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
OSV
CVE-2021-31812: In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file
osv·2021-06-12·CVSS 5.5
CVE-2021-31812 [MEDIUM] CVE-2021-31812: In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2021/06/12/1https://lists.apache.org/thread.html/r132e9dbbe0ebdc08b39583d8be0a575fdba573d60a42d940228bceff%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r143fd8445e0e778f4a85187bd79438630b96b8040e9401751fdb8aea%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r179cc3b6822c167702ab35fe36093d5da4c99af44238c8a754c6860f%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r2090789e4dcc2c87aacbd87d5f18e2d64dcb9f6eb7c47f5cf7d293cb%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/ra2ab0ce69ce8aaff0773b8c1036438387ce004c2afc6f066626e205e%40%3Cusers.pdfbox.apache.org%3Ehttps://lists.apache.org/thread.html/ra2ab0ce69ce8aaff0773b8c1036438387ce004c2afc6f066626e205e%40%3Cusers.pdfbox.apache.org%3Ehttps://lists.apache.org/thread.html/rd4b6db6c3b8ab3c70f1c3bbd725a40920896453ffc2744ade6afd9fb%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/re0cacd3fb337cdf8469853913ed2b4ddd8f8bfc52ff0ddbe61c1dfba%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rf251f6c358087107f8c23473468b279d59d50a75db6b4768165c78d3%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rfe26bcaba564deb505c32711ba68df7ec589797dcd96ff3389a8aaba%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7HHWJRFXZ3PTKLJCOM7WJEYZFKFWMNSV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MDJKJQOMVFDFIDS27OQJXNOYHV2O273D/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://www.openwall.com/lists/oss-security/2021/06/12/1https://lists.apache.org/thread.html/r132e9dbbe0ebdc08b39583d8be0a575fdba573d60a42d940228bceff%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r143fd8445e0e778f4a85187bd79438630b96b8040e9401751fdb8aea%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r179cc3b6822c167702ab35fe36093d5da4c99af44238c8a754c6860f%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r2090789e4dcc2c87aacbd87d5f18e2d64dcb9f6eb7c47f5cf7d293cb%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/ra2ab0ce69ce8aaff0773b8c1036438387ce004c2afc6f066626e205e%40%3Cusers.pdfbox.apache.org%3Ehttps://lists.apache.org/thread.html/ra2ab0ce69ce8aaff0773b8c1036438387ce004c2afc6f066626e205e%40%3Cusers.pdfbox.apache.org%3Ehttps://lists.apache.org/thread.html/rd4b6db6c3b8ab3c70f1c3bbd725a40920896453ffc2744ade6afd9fb%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/re0cacd3fb337cdf8469853913ed2b4ddd8f8bfc52ff0ddbe61c1dfba%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rf251f6c358087107f8c23473468b279d59d50a75db6b4768165c78d3%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rfe26bcaba564deb505c32711ba68df7ec589797dcd96ff3389a8aaba%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7HHWJRFXZ3PTKLJCOM7WJEYZFKFWMNSV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MDJKJQOMVFDFIDS27OQJXNOYHV2O273D/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-12
Published