Infinite loop in PDFBox - CVE-2021-27807
Published: March 22, 2021
Vulnerability identifier: #VU51606
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27807
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when processing PDF files. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
PDFBox
Engineering Test Management
IBM Security Risk Manager
Engineering Lifecycle Management - Jazz Foundation
IBM QRadar Incident Forensics
Oracle Retail Customer Management and Segmentation Foundation
openEuler
Fedora
pdfbox
xmpbox
fontbox
preflight
pdfbox-javadoc
pdfbox-debugger
pdfbox-reactor
pdfbox-parent
pdfbox-tools
Engineering Test Management
IBM Security Risk Manager
Engineering Lifecycle Management - Jazz Foundation
IBM QRadar Incident Forensics
Oracle Retail Customer Management and Segmentation Foundation
openEuler
Fedora
pdfbox
xmpbox
fontbox
preflight
pdfbox-javadoc
pdfbox-debugger
pdfbox-reactor
pdfbox-parent
pdfbox-tools
How to mitigate CVE-2021-27807
Install updates from vendor's website.
PDFBox - update to 2.0.23
Engineering Test Management - addressed in versions 7.0.3.0.20, 7.1.0.0.6
IBM Security Risk Manager - update to 1.8.0.0
pdfbox - update to 2.0.23-1
xmpbox - update to 2.0.23-1
fontbox - update to 2.0.23-1
preflight - update to 2.0.23-1
pdfbox-javadoc - update to 2.0.23-1
pdfbox-debugger - update to 2.0.23-1
pdfbox-reactor - update to 2.0.23-1
pdfbox-parent - update to 2.0.23-1
pdfbox-tools - update to 2.0.23-1
pdfbox - addressed in versions 2.0.23-1.fc32, 2.0.23-1.fc33, 2.0.23-1.fc34
Engineering Lifecycle Management - Jazz Foundation - addressed in versions 7.0.3 iFix018, 7.1.0 iFix005
IBM QRadar Incident Forensics - addressed in versions 7.3.3.9, 7.4.3.1
Engineering Test Management - addressed in versions 7.0.3.0.20, 7.1.0.0.6
IBM Security Risk Manager - update to 1.8.0.0
pdfbox - update to 2.0.23-1
xmpbox - update to 2.0.23-1
fontbox - update to 2.0.23-1
preflight - update to 2.0.23-1
pdfbox-javadoc - update to 2.0.23-1
pdfbox-debugger - update to 2.0.23-1
pdfbox-reactor - update to 2.0.23-1
pdfbox-parent - update to 2.0.23-1
pdfbox-tools - update to 2.0.23-1
pdfbox - addressed in versions 2.0.23-1.fc32, 2.0.23-1.fc33, 2.0.23-1.fc34
Engineering Lifecycle Management - Jazz Foundation - addressed in versions 7.0.3 iFix018, 7.1.0 iFix005
IBM QRadar Incident Forensics - addressed in versions 7.3.3.9, 7.4.3.1
External References
- http://www.openwall.com/lists/oss-security/2021/03/19/9
- https://lists.apache.org/thread.html/r043edc5dcf9199f7f882ed7906b41cb816753766e88b8792dbf319a9@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/r1d268642f8b52456ee8f876b888b8ed7a9e9568c7770789f3ded7f9e@%3Ccommits.ofbiz.apache.org%3E
- https://lists.apache.org/thread.html/r4717f902f8bc36d47b3fa978552a25e4ed3ddc2fffb52b94fbc4ab36@%3Cusers.pdfbox.apache.org%3E
- https://lists.apache.org/thread.html/r5c8e2125d18af184c80f7a986fbe47eaf0d30457cd450133adc235ac@%3Ccommits.ofbiz.apache.org%3E
- https://lists.apache.org/thread.html/r7ee634c21816c69ce829d0c41f35afa2a53a99bdd3c7cce8644fdc0e@%3Cnotifications.ofbiz.apache.org%3E
- https://lists.apache.org/thread.html/r818058ff1e4b9f6bef4e5a2e74faff38cb3d3885c1e2db398bc55cfb%40%3Cusers.pdfbox.apache.org%3E
- https://lists.apache.org/thread.html/r818058ff1e4b9f6bef4e5a2e74faff38cb3d3885c1e2db398bc55cfb@%3Cusers.pdfbox.apache.org%3E
- https://lists.apache.org/thread.html/r9ffe179385637b0b5cbdabd0246118005b4b8232909d2d14cd68ccd3@%3Ccommits.ofbiz.apache.org%3E
- https://lists.apache.org/thread.html/raa35746227f3f8d50fff1db9899524423a718f6f35cd39bd4769fa6c@%3Cnotifications.ofbiz.apache.org%3E
- https://lists.apache.org/thread.html/rc69140d894c6a9c67a8097a25656cce59b46a5620c354ceba10543c3@%3Cnotifications.ofbiz.apache.org%3E
- https://lists.apache.org/thread.html/re1e35881482e07dc2be6058d9b44483457f36133cac67956686ad9b9@%3Cnotifications.ofbiz.apache.org%3E
Related Security Bulletins
- Multiple vulnerabilities in Apache PDFBox
- Multiple vulnerabilities in Oracle Retail Customer Management and Segmentation Foundation
- Multiple vulnerabilities in IBM QRadar Incident Forensics
- Multiple vulnerabilities in IBM Security Risk Manager on CP4S
- openEuler 20.03 LTS SP1 update for pdfbox
- Fedora 34 update for pdfbox
- Fedora 33 update for pdfbox
- Fedora 32 update for pdfbox
- IBM Engineering Lifecycle Management - Jazz Foundation update for Apache PDFBox
- IBM Engineering Test Management update for Apache PDFBox