CVE-2021-27906: A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
Other sources
Apache PDFBox is vulnerable to a denial of service, caused by an OutOfMemory-Exception flaw. By persuading a victim to open a specially-crafted .PDF file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-27906?
CVE-2021-27906 is a vulnerability in Apache PDFBox that can be exploited by a remote attacker to cause the application to crash by convincing the victim to open a specially-crafted .PDF file.
How does CVE-2021-27906 impact Apache PDFBox?
CVE-2021-27906 can trigger an OutOfMemory-Exception while loading a PDF file, leading to a denial of service.
What is the severity of CVE-2021-27906?
The severity of CVE-2021-27906 is medium, with a severity value of 5.5.
How can the CVE-2021-27906 vulnerability be fixed?
To fix the CVE-2021-27906 vulnerability, users should update to Apache PDFBox version 2.0.23 or higher.
Where can I find more information about CVE-2021-27906?
You can find more information about CVE-2021-27906 on the CVE website (https://www.cve.org/CVERecord?id=CVE-2021-27906) and the NIST National Vulnerability Database (https://nvd.nist.gov/vuln/detail/CVE-2021-27906).