CVE-2018-11797

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/10/2018
Last modified:
07/11/2023

Description

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:* 1.8.0 (including) 1.8.15 (including)
cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:* 2.0.1 (including) 2.0.11 (including)
cpe:2.3:a:apache:pdfbox:2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:apache:pdfbox:2.0.0:-:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0:*:*:*:*:*:*:*