Bug 1099721 - (CVE-2018-8036) VUL-0: CVE-2018-8036: apache-pdfbox: DoS (OOM) Vulnerability in Apache PDFBox's AFMParser
(CVE-2018-8036)
VUL-0: CVE-2018-8036: apache-pdfbox: DoS (OOM) Vulnerability in Apache PDFBox...
Status: REOPENED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Fabian Vogt
Security Team bot
https://smash.suse.de/issue/209164/
CVSSv3:SUSE:CVE-2018-8036:5.9:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-06-29 16:17 UTC by Alexander Bergmann
Modified: 2019-05-29 08:58 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2018-06-29 16:17:44 UTC
[CVE-2018-8036] DoS (OOM) Vulnerability in Apache PDFBox's AFMParser

Severity: Important

Vendor:
The Apache Software Foundation

Versions Affected:
Apache PDFBox 1.8.0 to 1.8.14
Apache PDFBox 2.0.0 to 2.0.10
Earlier, unsupported Apache PDFBox versions may be affected as well

Description:

A carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.


Mitigation:
Upgrade to Apache PDFBox 1.8.15 respectively 2.0.11

Credit:
This issue was discovered by Tobias Ospelt



References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-8036
http://seclists.org/oss-sec/2018/q2/253
Comment 1 Fabian Vogt 2018-07-02 09:33:49 UTC
That was not nice:

- The upstream release 1.8.15 does not mention the issue anywhere
- The release notes entry describes the fix as "Optimization"
- The commit with the fix is called "clarify code"
- The upstream tarball still builds "1.8.14" binaries, had to patch that

Update to 1.8.15 submitted to Factory: sr 620189

Patched 1.8.12 submitted to SLE 15: sr 167951
Comment 4 Swamp Workflow Management 2018-09-06 10:12:00 UTC
SUSE-SU-2018:2630-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1099721
CVE References: CVE-2018-8036
Sources used:
SUSE Linux Enterprise Module for Development Tools 15 (src):    apache-pdfbox-1.8.12-5.3.13
Comment 5 Swamp Workflow Management 2018-09-07 10:08:01 UTC
openSUSE-SU-2018:2645-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1099721
CVE References: CVE-2018-8036
Sources used:
openSUSE Leap 15.0 (src):    apache-pdfbox-1.8.12-lp150.4.3.1
Comment 9 Swamp Workflow Management 2018-10-23 13:18:54 UTC
SUSE-SU-2018:3318-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1099721,1111009
CVE References: CVE-2018-11797,CVE-2018-8036
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    apache-pdfbox-1.8.12-3.5.4
Comment 10 Swamp Workflow Management 2018-10-24 13:19:03 UTC
openSUSE-SU-2018:3384-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1099721,1111009
CVE References: CVE-2018-11797,CVE-2018-8036
Sources used:
openSUSE Leap 42.3 (src):    apache-pdfbox-1.8.12-4.3.1