Infinite loop in PDFBox - CVE-2021-27807

 

Infinite loop in PDFBox - CVE-2021-27807

Published: March 22, 2021


Vulnerability identifier: #VU51606
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27807
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when processing PDF files. A remote attacker can consume all available system resources and cause denial of service conditions.


Affected software

PDFBox
Engineering Test Management
IBM Security Risk Manager
Engineering Lifecycle Management - Jazz Foundation
IBM QRadar Incident Forensics
Oracle Retail Customer Management and Segmentation Foundation
openEuler
Fedora
pdfbox
xmpbox
fontbox
preflight
pdfbox-javadoc
pdfbox-debugger
pdfbox-reactor
pdfbox-parent
pdfbox-tools

How to mitigate CVE-2021-27807

Install updates from vendor's website.

PDFBox - update to 2.0.23
Engineering Test Management - addressed in versions 7.0.3.0.20, 7.1.0.0.6
IBM Security Risk Manager - update to 1.8.0.0
pdfbox - update to 2.0.23-1
xmpbox - update to 2.0.23-1
fontbox - update to 2.0.23-1
preflight - update to 2.0.23-1
pdfbox-javadoc - update to 2.0.23-1
pdfbox-debugger - update to 2.0.23-1
pdfbox-reactor - update to 2.0.23-1
pdfbox-parent - update to 2.0.23-1
pdfbox-tools - update to 2.0.23-1
pdfbox - addressed in versions 2.0.23-1.fc32, 2.0.23-1.fc33, 2.0.23-1.fc34
Engineering Lifecycle Management - Jazz Foundation - addressed in versions 7.0.3 iFix018, 7.1.0 iFix005
IBM QRadar Incident Forensics - addressed in versions 7.3.3.9, 7.4.3.1

External References

Related Security Bulletins