CVE-2018-8036

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0.0:rc3:*:*:*:*:*:*

History

No history.

Information

Published : 2018-07-03 20:29

Updated : 2024-02-04 19:46


NVD link : CVE-2018-8036

Mitre link : CVE-2018-8036

CVE.ORG link : CVE-2018-8036


JSON object : View

Products Affected

apache

  • pdfbox
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')