In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libfontbox-java",
"binary_version": "1:1.8.16-2~18.04"
},
{
"binary_name": "libjempbox-java",
"binary_version": "1:1.8.16-2~18.04"
},
{
"binary_name": "libpdfbox-java",
"binary_version": "1:1.8.16-2~18.04"
}
]
}