In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
{
"binaries": [
{
"binary_version": "1:1.8.16-2~18.04",
"binary_name": "libfontbox-java"
},
{
"binary_version": "1:1.8.16-2~18.04",
"binary_name": "libjempbox-java"
},
{
"binary_version": "1:1.8.16-2~18.04",
"binary_name": "libpdfbox-java"
}
],
"availability": "No subscription required"
}