Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11797

Опубликовано: 05 окт. 2018
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6pdfboxOut of support scope
Red Hat JBoss BRMS 6pdfboxOut of support scope
Red Hat JBoss Data Virtualization 6pdfboxOut of support scope
Red Hat JBoss Fuse 6pdfboxOut of support scope
Red Hat JBoss Fuse Service Works 6pdfboxOut of support scope
Red Hat Satellite 5nutchWill not fix
Red Hat Fuse 7.7.0pdfboxFixedRHSA-2020:319228.07.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=1637492pdfbox: unbounded computation in parser resulting in a denial of service

EPSS

Процентиль: 81%
0.0162
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

CVSS3: 5.5
nvd
больше 7 лет назад

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

CVSS3: 5.5
debian
больше 7 лет назад

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully c ...

suse-cvrf
около 7 лет назад

Security update for apache-pdfbox

suse-cvrf
около 7 лет назад

Security update for apache-pdfbox

EPSS

Процентиль: 81%
0.0162
Низкий

5.5 Medium

CVSS3