Infinite loop in PDFBox - CVE-2018-8036

 

Infinite loop in PDFBox - CVE-2018-8036

Published: July 3, 2018


Vulnerability identifier: #VU13547
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8036
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to infinite loop when handling malicious input. A remote attacker can supple specially crafted (or fuzzed) file, trigger out of memory exception and cause the service to crash.


Affected software

PDFBox
IBM Business Automation Workflow
IBM Intelligent Operations Center
Opensuse
Fedora
pdfbox
IBM Case Manager
IBM Qradar SIEM
Fuse

How to mitigate CVE-2018-8036

Update to version 1.8.15 or 2.0.10.

PDFBox - addressed in versions 1.8.15, 2.0.10
IBM Intelligent Operations Center - update to 5.2.4
pdfbox - addressed in versions 2.0.16-1.fc29, 2.0.16-1.fc30, 2.0.16-1.fc31
IBM Case Manager - update to 5.3.3-IF011
Fuse - update to 7.1.0
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5

External References

Related Security Bulletins