suse · CVE-2018-8036

Quick triage

Priority: medium Published: 2021-05-30 14:11:46 UTC Updated: 2026-04-17 15:29:45 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-8036 severity moderate: SUSE including 12 source package names (apache-pdfbox, apache-pdfbox-1.8.12-3.5.4, …), 19 product×package rows across 15 product lines (SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15 SP1, … (15 product lines)): Fixed 18, Known Not Affected 1.

Description:

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

cvelogic Threat Intelligence