Debian Security Advisory
DLA-1547-1 libpdfbox-java -- LTS security update
- Date Reported:
- 16 Oct 2018
- Affected Packages:
- libpdfbox-java
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-11797.
- More information:
-
It was discovered that there was a denial-of-service vulnerability in libpdfbox-java, a PDF library for Java.
A malicious PDF file could have triggered an extremely long running computation when parsing the page tree.
For Debian 8
Jessie
, this issue has been fixed in libpdfbox-java version 1:1.8.7+dfsg-1+deb8u2.We recommend that you upgrade your libpdfbox-java packages.