CVE-2021-27807: A carefully crafted PDF file can trigger an infinite loop while loading the file
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
Other sources
Apache PDFBox is vulnerable to a denial of service, caused by an infinite loop flaw. By persuading a victim to open a specially-crafted .PDF file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-27807?
CVE-2021-27807 is a vulnerability in Apache PDFBox that can be exploited to cause a denial of service.
How does CVE-2021-27807 affect Apache PDFBox?
CVE-2021-27807 affects Apache PDFBox by triggering an infinite loop while loading a specially-crafted PDF file, which can lead to a crash of the application.
What is the severity of CVE-2021-27807?
The severity of CVE-2021-27807 is medium, with a severity value of 5.5.
How can CVE-2021-27807 be fixed?
To fix CVE-2021-27807, you need to update Apache PDFBox to version 2.0.23 or later.
Where can I find more information about CVE-2021-27807?
You can find more information about CVE-2021-27807 on the CVE website, NVD, Red Hat Bugzilla, and Red Hat's official advisory.