CVE-2018-8036: Medium severity Apache PDFBox vulnerability
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Other sources
PDFBox before versions 1.8.15 and 2.0.11 has an infinitre loop in AFMParser.java. An attacker could exploit this to cause an out of memory error via a crafted PDF.
External Reference:
http://www.openwall.com/lists/oss-security/2018/06/29/1
Upstream Release Notes:
https://www.apache.org/dist/pdfbox/2.0.11/RELEASE-NOTES.txt https://www.apache.org/dist/pdfbox/1.8.15/RELEASE-NOTES.txt
Upstream Issue:
https://issues.apache.org/jira/projects/PDFBOX/issues/PDFBOX-4251
Upstream Patches:
http://svn.apache.org/viewvc/pdfbox/trunk/fontbox/src/main/java/org/apache/fontbox/afm/AFMParser.java?rev=1834048&r1=1834047&r2=1834048&view=diff http://svn.apache.org/viewvc/pdfbox/branches/2.0/fontbox/src/main/java/org/apache/fontbox/afm/AFMParser.java?rev=1834046&r1=1834045&r2=1834046&view=diff http://svn.apache.org/viewvc/pdfbox/branches/1.8/fontbox/src/main/java/org/apache/fontbox/afm/AFMParser.java?rev=1834047&r1=1834046&r2=1834047&view=diff
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pdfboxto a version that resolves this vulnerability.Fixed in 1.8.15 - Upgrade
Upgrade
redhat/pdfboxto a version that resolves this vulnerability.Fixed in 2.0.10 - Upgrade
Upgrade
Apache PDFBoxto a version that resolves this vulnerability.Fixed in 1.8.15 - Upgrade
Upgrade
Apache PDFBoxto a version that resolves this vulnerability.Fixed in 2.0.11
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-8036.
What is the severity of CVE-2018-8036?
The severity of CVE-2018-8036 is medium.
Which software versions are affected by CVE-2018-8036?
Apache PDFBox versions 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10 are affected by CVE-2018-8036.
How can the vulnerability be exploited?
A carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
How can I fix CVE-2018-8036?
To fix CVE-2018-8036, update Apache PDFBox to version 1.8.15 or 2.0.11.