REDHAT-BUG-1971648: Low severity apache pdfbox vulnerability
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
References: https://www.openwall.com/lists/oss-security/2021/06/12/2 https://lists.apache.org/thread.html/re3bd16f0cc8f1fbda46b06a4b8241cd417f71402809baa81548fc20e%40%3Cusers.pdfbox.apache.org%3E
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1971648?
REDHAT-BUG-1971648 has a high severity due to its potential to cause OutOfMemory exceptions when processing crafted PDF files.
How do I fix REDHAT-BUG-1971648?
To fix REDHAT-BUG-1971648, upgrade Apache PDFBox to version 2.0.24 or later.
What versions of Apache PDFBox are affected by REDHAT-BUG-1971648?
REDHAT-BUG-1971648 affects Apache PDFBox version 2.0.23 and earlier in the 2.0.x series.
What is the nature of the issue described in REDHAT-BUG-1971648?
The issue in REDHAT-BUG-1971648 is an OutOfMemory exception that can be triggered by loading a specially crafted PDF file.
Is there a workaround for REDHAT-BUG-1971648 if I cannot upgrade immediately?
While the recommended solution is to upgrade, a temporary workaround is to limit the size of PDFs processed by Apache PDFBox.