Bugzilla – Bug 1099721
VUL-0: CVE-2018-8036: apache-pdfbox: DoS (OOM) Vulnerability in Apache PDFBox's AFMParser
Last modified: 2019-05-29 08:58:06 UTC
[CVE-2018-8036] DoS (OOM) Vulnerability in Apache PDFBox's AFMParser Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache PDFBox 1.8.0 to 1.8.14 Apache PDFBox 2.0.0 to 2.0.10 Earlier, unsupported Apache PDFBox versions may be affected as well Description: A carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser. Mitigation: Upgrade to Apache PDFBox 1.8.15 respectively 2.0.11 Credit: This issue was discovered by Tobias Ospelt References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-8036 http://seclists.org/oss-sec/2018/q2/253
That was not nice: - The upstream release 1.8.15 does not mention the issue anywhere - The release notes entry describes the fix as "Optimization" - The commit with the fix is called "clarify code" - The upstream tarball still builds "1.8.14" binaries, had to patch that Update to 1.8.15 submitted to Factory: sr 620189 Patched 1.8.12 submitted to SLE 15: sr 167951
SUSE-SU-2018:2630-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1099721 CVE References: CVE-2018-8036 Sources used: SUSE Linux Enterprise Module for Development Tools 15 (src): apache-pdfbox-1.8.12-5.3.13
openSUSE-SU-2018:2645-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1099721 CVE References: CVE-2018-8036 Sources used: openSUSE Leap 15.0 (src): apache-pdfbox-1.8.12-lp150.4.3.1
SUSE-SU-2018:3318-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1099721,1111009 CVE References: CVE-2018-11797,CVE-2018-8036 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP3 (src): apache-pdfbox-1.8.12-3.5.4
openSUSE-SU-2018:3384-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1099721,1111009 CVE References: CVE-2018-11797,CVE-2018-8036 Sources used: openSUSE Leap 42.3 (src): apache-pdfbox-1.8.12-4.3.1