Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 8 MGASA-2021-0184 Critical: Pdfbox Infinite Loop Issue

mageia
Calendar Grey April 12, 2021
Dist Mageia Esm H88
Mageia 8's pdfbox packages have been revised to tackle urgent security vulnerabilities in the management of PDF files. Refer to advisory MGASA-2021-0184 for more information.
A carefully crafted PDF file can trigger an infinite loop while loading the file

Summary

A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox Apache PDFBox version 2.0.22 and prior 2.0.x versions (CVE-2021-27807).
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox Apache PDFBox version 2.0.22 and prior 2.0.x versions (CVE-2021-27906).

References

- https://bugs.mageia.org/show_bug.cgi?id=28682

- https://www.openwall.com/lists/oss-security/2021/03/19/9

- https://www.openwall.com/lists/oss-security/2021/03/19/10

- https://www.cve.org/CVERecord?id=CVE-2021-27807

- https://www.cve.org/CVERecord?id=CVE-2021-27906

Resolution

SRPMS

- 8/core/pdfbox-2.0.23-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 12 Apr 2021
URL: https://advisories.mageia.org/MGASA-2021-0184.html
Type: security
CVE: CVE-2021-27807, CVE-2021-27906

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here