CVE-2021-27807

MEDIUM

Apache PDFBox <2.0.22 - Info Disclosure

Title source: llm
STIX 2.1

Description

A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

References (21)

Core 21
Core References
Mailing List, Vendor Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/03/19/9
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 5.5
EPSS 0.0298
EPSS Percentile 85.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-834
Status published
Products (32)
apache/pdfbox 2.0.0 - 2.0.22
fedoraproject/fedora 32
fedoraproject/fedora 33
fedoraproject/fedora 34
oracle/banking_trade_finance_process_management 14.2.0
oracle/banking_trade_finance_process_management 14.3.0
oracle/banking_trade_finance_process_management 14.5.0
oracle/banking_treasury_management 14.5
oracle/banking_virtual_account_management 14.2.0
oracle/banking_virtual_account_management 14.3.0
... and 22 more
Published Mar 19, 2021
Tracked Since Feb 18, 2026