Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-8036

Опубликовано: 01 июл. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

Отчет

While Fuse 6.3 and Fuse 7.0 ship vulnerable artifact via camel-pdfbox, however, the flawed code is not being used therefore no execution path leads to an exposure to this vulnerability, so both Fuse 6.3, 7 standalone are not affected. However, Fuse 7.0 on OpenShift ship vulnerable artifact via maven BOM, so setting Fuse 7.0 as affected for this reason only.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6pdfboxNot affected
Red Hat JBoss BRMS 6pdfboxNot affected
Red Hat JBoss Data Virtualization 6pdfboxWill not fix
Red Hat JBoss Fuse 6pdfboxNot affected
Red Hat JBoss Fuse Service Works 6pdfboxNot affected
Red Hat Satellite 5nutchWill not fix
Red Hat JBoss Fuse 7pdfboxFixedRHSA-2018:266911.09.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1597490pdfbox: Infinite loop in AFMParser.java allows for out of memory erros via crafted PDF

EPSS

Процентиль: 67%
0.00547
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

CVSS3: 6.5
nvd
больше 7 лет назад

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

CVSS3: 6.5
debian
больше 7 лет назад

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully c ...

suse-cvrf
больше 7 лет назад

Security update for apache-pdfbox

suse-cvrf
больше 7 лет назад

Security update for apache-pdfbox

EPSS

Процентиль: 67%
0.00547
Низкий

6.5 Medium

CVSS3