CVE-2018-11797 PUBLISHED

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

EPSS 1.62% · 81.7th percentile

Risk Scores

EPSS Score
1.62%
81.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlibpdfbox-java0, 1:1.8.13-1, 1:1.8.13-2
Ubuntu:16.04:LTSlibpdfbox-java1:1.8.10-2, 1:1.8.11+dfsg-1, 0
Ubuntu:18.04:LTSlibpdfbox2-java0, 2.0.7-1, 2.0.8-1

Timeline

References

Open in Interactive Console →