CVE-2021-31812: A carefully crafted PDF file can trigger an infinite loop while loading the file
Apache PDFBox is vulnerable to a denial of service, caused by an error while loading a file. By persuading a victim to open a specially-crafted PDF file, a remote attacker could exploit this vulnerability to cause the system to enter into an infinite loop.
Other sources
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-31812?
CVE-2021-31812 is a vulnerability in Apache PDFBox that can trigger an infinite loop while loading a PDF file.
How does CVE-2021-31812 affect Apache PDFBox?
CVE-2021-31812 affects Apache PDFBox by causing a denial of service due to an error while loading a specially-crafted PDF file.
What is the severity of CVE-2021-31812?
CVE-2021-31812 has a severity rating of medium with a CVSS score of 5.5.
How can CVE-2021-31812 be exploited?
CVE-2021-31812 can be exploited by persuading a victim to open a specially-crafted PDF file, which will cause the system to enter into an infinite loop.
How can I fix CVE-2021-31812 in Apache PDFBox?
To fix CVE-2021-31812 in Apache PDFBox, update to version 2.0.24 or later.