In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
2018-07-03T20:29:00.247
2024-11-21T04:13:09.000
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | pdfbox | ≤ 1.8.14 | Yes |
Application | apache | pdfbox | ≤ 2.0.10 | Yes |
Application | apache | pdfbox | 2.0.0 | Yes |
Application | apache | pdfbox | 2.0.0 | Yes |
Application | apache | pdfbox | 2.0.0 | Yes |