CVE-2018-8036
pdfbox: Infinite loop in AFMParser.java allows for out of memory erros via crafted PDF
Severity Score
6.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
En Apache PDFBox, desde la versión 1.8.0 hasta la 1.8.14 y desde la 2.0.0RC1 hasta la 2.0.10, un archivo especialmente manipulado (o no válido) que puede desencadenar un bucle infinito que conduce a una excepción de agotamiento de memoria en Apache PDFBox's AFMParser.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-03-09 CVE Reserved
- 2018-07-03 CVE Published
- 2024-01-03 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
CAPEC
References (8)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | > 1.8.0 <= 1.8.14 Search vendor "Apache" for product "Pdfbox" and version " > 1.8.0 <= 1.8.14" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | >= 2.0.0 <= 2.0.10 Search vendor "Apache" for product "Pdfbox" and version " >= 2.0.0 <= 2.0.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 2.0.0 Search vendor "Apache" for product "Pdfbox" and version "2.0.0" | rc1 |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 2.0.0 Search vendor "Apache" for product "Pdfbox" and version "2.0.0" | rc2 |
Affected
| ||||||
Apache Search vendor "Apache" | Pdfbox Search vendor "Apache" for product "Pdfbox" | 2.0.0 Search vendor "Apache" for product "Pdfbox" and version "2.0.0" | rc3 |
Affected
|