Bug 1941055 (CVE-2021-27807)
Summary: | CVE-2021-27807 pdfbox: infinite loop while loading a crafted PDF file | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | aileenc, akoufoud, alazarot, almorale, anstephe, bibryam, chazlett, drieden, etirelli, ggaughan, gmalinko, gvarsami, hbraun, ibek, janstey, java-sig-commits, jcoleman, jnethert, jochrist, jolee, jschatte, jstastny, jwon, kconner, krathod, kverlaen, ldimaggi, mnovotny, nwallace, pantinor, pjindal, puntogil, rrajasek, rsynek, rwagner, sdaley, tcunning, tkirby |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | pdfbox-2.0.23 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2021-08-11 19:29:06 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1941056 | ||
Bug Blocks: | 1941059 |
Description
Guilherme de Almeida Suckevicz
2021-03-19 20:26:28 UTC
Created pdfbox tracking bugs for this issue: Affects: fedora-all [bug 1941056] FEDORA-2021-93469e0030 has been pushed to the Fedora 34 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-2021-dc83ae690a has been pushed to the Fedora 32 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-2021-8b17a2725e has been pushed to the Fedora 33 stable repository. If problem still persists, please make note of it in this bug report. This vulnerability is out of security support scope for the following products: * Red Hat JBoss Fuse 6 * Red Hat JBoss Fuse Service Works 6 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details. This issue has been addressed in the following products: Red Hat Fuse 7.9 Via RHSA-2021:3140 https://access.redhat.com/errata/RHSA-2021:3140 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-27807 This issue has been addressed in the following products: Red Hat Integration Via RHSA-2021:3205 https://access.redhat.com/errata/RHSA-2021:3205 |