CVE-2021-31812

MEDIUM

Apache PDFBox 2.0.0-2.0.23 - Denial of Service via Infinite Loop

Title source: llm
STIX 2.1

Description

In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

References (16)

Core 16
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/06/12/1
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 5.5
EPSS 0.0305
EPSS Percentile 85.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-834 CWE-835
Status published
Products (16)
apache/pdfbox 2.0.0 - 2.0.23
fedoraproject/fedora 33
fedoraproject/fedora 34
oracle/banking_corporate_lending_process_management 14.2.0
oracle/banking_corporate_lending_process_management 14.3.0
oracle/banking_corporate_lending_process_management 14.5.0
oracle/banking_credit_facilities_process_management 14.2.0
oracle/banking_credit_facilities_process_management 14.3.0
oracle/banking_credit_facilities_process_management 14.5.0
oracle/banking_supply_chain_finance 14.2.0
... and 6 more
Published Jun 12, 2021
Tracked Since Feb 18, 2026