5.5
CVSSv3

CVE-2018-11797

Published: 05/10/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache pdfbox 2.0

apache pdfbox

apache pdfbox 2.0.0

fedoraproject fedora 29

fedoraproject fedora 30

oracle retail xstore point of service 17.0

Vendor Advisories

Debian Bug report logs - #910390 libpdfbox-java: CVE-2018-11797 Package: src:libpdfbox-java; Maintainer for src:libpdfbox-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 5 Oct 2018 20:00:02 UTC Severity: important Tags: ...
Synopsis Important: Red Hat Fuse 770 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 76 to 77) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Produc ...
In Apache PDFBox 180 to 1815 and 200RC1 to 2011, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree ...