QID 981074
QID 981074: Java (maven) Security Update for org.apache.pdfbox:pdfbox (GHSA-gx96-vgf7-hwfg)
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gx96-vgf7-hwfg for updates pertaining to this vulnerability.
Vendor References
- GHSA-gx96-vgf7-hwfg -
github.com/advisories/GHSA-gx96-vgf7-hwfg
CVEs related to QID 981074
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gx96-vgf7-hwfg | org.apache.pdfbox:pdfbox |
|