In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "2.0-rc1"
},
{
"last_affected": "2.0-rc2"
},
{
"last_affected": "2.0-rc3"
}
],
"source": "CPE_STRING",
"vendor_product": "apache:pdfbox",
"cpes": [
"cpe:2.3:a:apache:pdfbox:2.0:rc1:*:*:*:*:*:*",
"cpe:2.3:a:apache:pdfbox:2.0:rc2:*:*:*:*:*:*",
"cpe:2.3:a:apache:pdfbox:2.0:rc3:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "29"
},
{
"last_affected": "30"
}
],
"source": "CPE_STRING",
"vendor_product": "fedoraproject:fedora",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "17.0"
}
],
"vendor_product": "oracle:retail_xstore_point_of_service",
"cpes": [
"cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
}
]
}{
"cpe": [
"cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:pdfbox:2.0.0:-:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.8.0"
},
{
"last_affected": "1.8.15"
},
{
"introduced": "2.0.1"
},
{
"last_affected": "2.0.11"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.0-NA"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}