CVE-2018-11797

MEDIUM

Apache PDFBox 1.8.0-1.8.15 and 2.0.0RC1-2.0.11 - Denial of Service via Page Tree Parsing

Title source: llm
STIX 2.1

Description

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

Scores

CVSS v3 5.5
EPSS 0.0162
EPSS Percentile 82.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

Status published
Products (7)
apache/pdfbox 2.0 rc1 (3 CPE variants)
apache/pdfbox 2.0.0
apache/pdfbox 1.8.0 - 1.8.15
fedoraproject/fedora 29
fedoraproject/fedora 30
oracle/retail_xstore_point_of_service 17.0
org.apache.pdfbox/pdfbox 1.8.0 - 1.8.16Maven
Published Oct 05, 2018
Tracked Since Feb 18, 2026