2021-04-26 17:02:45 +00:00
{
"CVE_data_meta" : {
2021-06-12 10:41:33 +01:00
"ASSIGNER" : "security@apache.org" ,
2021-04-26 17:02:45 +00:00
"ID" : "CVE-2021-31812" ,
2021-06-12 10:41:33 +01:00
"STATE" : "PUBLIC" ,
"TITLE" : "A carefully crafted PDF file can trigger an infinite loop while loading the file"
2021-04-26 17:02:45 +00:00
} ,
2021-06-12 10:41:33 +01:00
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "Apache PDFBox" ,
"version" : {
"version_data" : [
{
"version_affected" : "<" ,
"version_name" : "Apache PDFBox" ,
"version_value" : "2.0.24"
}
]
}
}
]
} ,
"vendor_name" : "Apache Software Foundation"
}
]
}
} ,
"credit" : [
{
"lang" : "eng" ,
"value" : "Apache PDFBox would like to thank Chaoyuan Peng for reporting this issue"
}
] ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
2021-04-26 17:02:45 +00:00
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2021-06-12 10:41:33 +01:00
"value" : "In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions."
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.0.9"
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-834 Excessive Iteration"
}
]
2021-04-26 17:02:45 +00:00
}
]
2021-06-12 10:41:33 +01:00
} ,
"references" : {
"reference_data" : [
{
2021-06-12 10:00:51 +00:00
"refsource" : "MISC" ,
"url" : "https://lists.apache.org/thread.html/ra2ab0ce69ce8aaff0773b8c1036438387ce004c2afc6f066626e205e%40%3Cusers.pdfbox.apache.org%3E" ,
"name" : "https://lists.apache.org/thread.html/ra2ab0ce69ce8aaff0773b8c1036438387ce004c2afc6f066626e205e%40%3Cusers.pdfbox.apache.org%3E"
2021-06-12 12:00:52 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[pdfbox-users] 20210612 CVE-2021-31812: Apache PDFBox: A carefully crafted PDF file can trigger an infinite loop while loading the file" ,
"url" : "https://lists.apache.org/thread.html/ra2ab0ce69ce8aaff0773b8c1036438387ce004c2afc6f066626e205e@%3Cusers.pdfbox.apache.org%3E"
2021-06-12 13:00:46 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[announce] 20210612 CVE-2021-31812: Apache PDFBox: A carefully crafted PDF file can trigger an infinite loop while loading the file" ,
"url" : "https://lists.apache.org/thread.html/rf251f6c358087107f8c23473468b279d59d50a75db6b4768165c78d3@%3Cannounce.apache.org%3E"
2021-06-12 18:00:47 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[oss-security] 20210612 CVE-2021-31812: Apache PDFBox: A carefully crafted PDF file can trigger an infinite loop while loading the file" ,
"url" : "http://www.openwall.com/lists/oss-security/2021/06/12/1"
2021-06-13 10:00:51 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[ofbiz-notifications] 20210613 [jira] [Updated] (OFBIZ-12256) Update PDFBox to 2.0.24 because of CVE-2021-31811 & CVE-2021-31812" ,
"url" : "https://lists.apache.org/thread.html/rfe26bcaba564deb505c32711ba68df7ec589797dcd96ff3389a8aaba@%3Cnotifications.ofbiz.apache.org%3E"
} ,
{
"refsource" : "MLIST" ,
"name" : "[ofbiz-notifications] 20210613 [jira] [Closed] (OFBIZ-12256) Update PDFBox to 2.0.24 because of CVE-2021-31811 & CVE-2021-31812" ,
"url" : "https://lists.apache.org/thread.html/rd4b6db6c3b8ab3c70f1c3bbd725a40920896453ffc2744ade6afd9fb@%3Cnotifications.ofbiz.apache.org%3E"
} ,
{
"refsource" : "MLIST" ,
"name" : "[ofbiz-commits] 20210613 [ofbiz-framework] branch release17.12 updated: Fixed: Update PDFBox to 2.0.24 because of CVE-2021-31811 & CVE-2021-31812 (OFBIZ-12256)" ,
"url" : "https://lists.apache.org/thread.html/r143fd8445e0e778f4a85187bd79438630b96b8040e9401751fdb8aea@%3Ccommits.ofbiz.apache.org%3E"
} ,
{
"refsource" : "MLIST" ,
"name" : "[ofbiz-commits] 20210613 [ofbiz-framework] branch trunk updated: Fixed: Update PDFBox to 2.0.24 because of CVE-2021-31811 & CVE-2021-31812 (OFBIZ-12256)" ,
"url" : "https://lists.apache.org/thread.html/r179cc3b6822c167702ab35fe36093d5da4c99af44238c8a754c6860f@%3Ccommits.ofbiz.apache.org%3E"
} ,
{
"refsource" : "MLIST" ,
"name" : "[ofbiz-notifications] 20210613 [jira] [Created] (OFBIZ-12256) Update PDFBox to 2.0.24 because of CVE-2021-31811 & CVE-2021-31812" ,
"url" : "https://lists.apache.org/thread.html/r2090789e4dcc2c87aacbd87d5f18e2d64dcb9f6eb7c47f5cf7d293cb@%3Cnotifications.ofbiz.apache.org%3E"
} ,
{
"refsource" : "MLIST" ,
"name" : "[ofbiz-notifications] 20210613 [jira] [Commented] (OFBIZ-12256) Update PDFBox to 2.0.24 because of CVE-2021-31811 & CVE-2021-31812" ,
"url" : "https://lists.apache.org/thread.html/r132e9dbbe0ebdc08b39583d8be0a575fdba573d60a42d940228bceff@%3Cnotifications.ofbiz.apache.org%3E"
} ,
{
"refsource" : "MLIST" ,
"name" : "[ofbiz-commits] 20210613 [ofbiz-framework] branch release18.12 updated: Fixed: Update PDFBox to 2.0.24 because of CVE-2021-31811 & CVE-2021-31812 (OFBIZ-12256)" ,
"url" : "https://lists.apache.org/thread.html/re0cacd3fb337cdf8469853913ed2b4ddd8f8bfc52ff0ddbe61c1dfba@%3Ccommits.ofbiz.apache.org%3E"
2021-06-24 19:00:55 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2021-4a9ead5fff" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7HHWJRFXZ3PTKLJCOM7WJEYZFKFWMNSV/"
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2021-3d94c14be4" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MDJKJQOMVFDFIDS27OQJXNOYHV2O273D/"
2021-10-19 14:23:14 -07:00
} ,
{
2021-10-20 11:02:08 +00:00
"url" : "https://www.oracle.com/security-alerts/cpuoct2021.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpuoct2021.html"
2022-01-18 14:34:17 -08:00
} ,
{
2022-02-07 16:01:25 +00:00
"url" : "https://www.oracle.com/security-alerts/cpujan2022.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpujan2022.html"
2022-04-19 16:28:20 -07:00
} ,
{
2022-04-20 00:02:37 +00:00
"url" : "https://www.oracle.com/security-alerts/cpuapr2022.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpuapr2022.html"
2022-07-19 14:38:32 -07:00
} ,
{
2022-07-25 19:01:27 +00:00
"url" : "https://www.oracle.com/security-alerts/cpujul2022.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpujul2022.html"
2021-06-12 10:41:33 +01:00
}
]
} ,
"source" : {
"discovery" : "UNKNOWN"
} ,
"work_around" : [
{
"lang" : "eng" ,
"value" : "This issue was fixed in 2.0.24. All users are recommended to upgrade to Apache PDFBox 2.0.24"
}
]
2021-06-12 10:00:51 +00:00
}