CVE-2018-11797
MEDIUMApache PDFBox 1.8.0-1.8.15 and 2.0.0RC1-2.0.11 - Denial of Service via Page Tree Parsing
Title source: llmDescription
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
References (7)
Core 7
Core References
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/645574bc50b886d39c20b4065d51ccb1cd5d3a6b4750a22edbb565eb%40%3Cannounce.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/a9760973a873522f4d4c0a99916ceb74f361d91006b663a0a418d34a%40%3Cannounce.apache.org%3E
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/10/msg00008.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6HKVPTJWZGUB4MH4AAOWMRJHRDBYFHGJ/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/r54594251369e14c185da9662a5340a52afbbdf75d61c9c3a69c8f2e8%40%3Cdev.pdfbox.apache.org%3E
Scores
CVSS v3
5.5
EPSS
0.0162
EPSS Percentile
82.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
Status
published
Products (7)
apache/pdfbox
2.0 rc1 (3 CPE variants)
apache/pdfbox
2.0.0
apache/pdfbox
1.8.0 - 1.8.15
fedoraproject/fedora
29
fedoraproject/fedora
30
oracle/retail_xstore_point_of_service
17.0
org.apache.pdfbox/pdfbox
1.8.0 - 1.8.16Maven
Published
Oct 05, 2018
Tracked Since
Feb 18, 2026