Infinite loop in PDFBox - CVE-2018-8036
Published: July 3, 2018
Vulnerability identifier: #VU13547
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8036
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to infinite loop when handling malicious input. A remote attacker can supple specially crafted (or fuzzed) file, trigger out of memory exception and cause the service to crash.
Affected software
PDFBox
IBM Business Automation Workflow
IBM Intelligent Operations Center
Opensuse
Fedora
pdfbox
IBM Case Manager
IBM Qradar SIEM
Fuse
IBM Business Automation Workflow
IBM Intelligent Operations Center
Opensuse
Fedora
pdfbox
IBM Case Manager
IBM Qradar SIEM
Fuse
How to mitigate CVE-2018-8036
Update to version 1.8.15 or 2.0.10.
PDFBox - addressed in versions 1.8.15, 2.0.10
IBM Intelligent Operations Center - update to 5.2.4
pdfbox - addressed in versions 2.0.16-1.fc29, 2.0.16-1.fc30, 2.0.16-1.fc31
IBM Case Manager - update to 5.3.3-IF011
Fuse - update to 7.1.0
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM Intelligent Operations Center - update to 5.2.4
pdfbox - addressed in versions 2.0.16-1.fc29, 2.0.16-1.fc30, 2.0.16-1.fc31
IBM Case Manager - update to 5.3.3-IF011
Fuse - update to 7.1.0
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
External References
Related Security Bulletins
- Denial of service in Apache PDFBox
- OpenSUSE Linux update for apache-pdfbox
- OpenSUSE Linux update for apache-pdfbox
- Infinite loop in IBM Intelligent Operations Center
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Business Automation Workflow and IBM Case Manager
- Fedora 30 update for pdfbox
- Fedora 31 update for pdfbox
- Fedora 29 update for pdfbox
- Multiple vulnerabilities in Fuse 7