CVE-2018-8036

Related Vulnerabilities: CVE-2018-8036  

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

The MITRE CVE dictionary describes this issue as:

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

Find out more about CVE-2018-8036 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

While Fuse 6.3 and Fuse 7.0 ship vulnerable artifact via camel-pdfbox, however, the flawed code is not being used therefore no execution path leads to an exposure to this vulnerability, so both Fuse 6.3, 7 standalone are not affected. However, Fuse 7.0 on OpenShift ship vulnerable artifact via maven BOM, so setting Fuse 7.0 as affected for this reason only.

CVSS v3 metrics

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Fuse 7 RHSA-2018:2669 2018-09-11

Affected Packages State

Platform Package State
Red Hat Satellite 5 nutch Will not fix
Red Hat JBoss Fuse Service Works 6 pdfbox Not affected
Red Hat JBoss Fuse 6 pdfbox Not affected
Red Hat JBoss Data Virtualization 6 pdfbox Will not fix
Red Hat JBoss BRMS 6 pdfbox Not affected
Red Hat JBoss BPMS 6 pdfbox Not affected

External References