First published: Fri Mar 19 2021(Updated: )
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/pdfbox | <2.0.23 | 2.0.23 |
Apache PDFBox | >=2.0.0<=2.0.22 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Oracle Banking Trade Finance Process Management | =14.2.0 | |
Oracle Banking Trade Finance Process Management | =14.3.0 | |
Oracle Banking Trade Finance Process Management | =14.5.0 | |
Oracle Banking Treasury Management | =14.5 | |
Oracle Banking Virtual Account Management | =14.2.0 | |
Oracle Banking Virtual Account Management | =14.3.0 | |
Oracle Banking Virtual Account Management | =14.5.0 | |
Oracle Communications Session Report Manager | >=8.0.0<=8.2.4.0 | |
Oracle FLEXCUBE Universal Banking | >=14.0.0<=14.3.0 | |
Oracle FLEXCUBE Universal Banking | =14.5.0 | |
Oracle Hyperion Financial Reporting | =11.1.2.4 | |
Oracle Hyperion Financial Reporting | =11.2.6.0 | |
Oracle Hyperion Infrastructure Technology | <11.2.8.0 | |
Oracle Outside In Technology | =8.5.5 | |
Oracle Primavera Unifier | >=17.7<=17.12 | |
Oracle Primavera Unifier | =18.8 | |
Oracle Primavera Unifier | =19.12 | |
Oracle Primavera Unifier | =20.12 | |
Oracle Retail Customer Management and Segmentation Foundation | =19.0 | |
Oracle Retail Xstore Point of Service | =16.0.6 | |
Oracle Retail Xstore Point of Service | =17.0.4 | |
Oracle Retail Xstore Point of Service | =18.0.3 | |
Oracle Retail Xstore Point of Service | =19.0.2 | |
Oracle Retail Xstore Point of Service | =20.0.1 | |
Oracle WebCenter Sites | =12.2.1.3.0 | |
Oracle WebCenter Sites | =12.2.1.4.0 | |
Oracle Communications Messaging Server | =8.1 | |
IBM Security Risk Manager on CP4S | <=CP4S 1.7.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27807 is a vulnerability in Apache PDFBox that can be exploited to cause a denial of service.
CVE-2021-27807 affects Apache PDFBox by triggering an infinite loop while loading a specially-crafted PDF file, which can lead to a crash of the application.
The severity of CVE-2021-27807 is medium, with a severity value of 5.5.
To fix CVE-2021-27807, you need to update Apache PDFBox to version 2.0.23 or later.
You can find more information about CVE-2021-27807 on the CVE website, NVD, Red Hat Bugzilla, and Red Hat's official advisory.