CVE-2018-11797

5.5MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
5 October 2018

Summary

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

Affected Version(s)

Apache PDFBox 1.8.0 to 1.8.15

Apache PDFBox 2.0.0RC1 to 2.0.11

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.