Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

0.0.1-RC13 is facing critical security issue. Please update pdfbox to latest #241

Closed
cseblog opened this issue Jul 6, 2018 · 3 comments
Closed

Comments

@cseblog
Copy link

cseblog commented Jul 6, 2018

We are using version 0.0.1-RC13 but our analysis shows that we have a critical security issue. Please help deliver a new version with latest pdfbox lib (2.0.11)

"Description from CVE
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Categories
Data

Root Cause
fontbox-2.0.8.jar : [2.0.0, 2.0.11)"

@koan00
Copy link

koan00 commented Jul 6, 2018

This is already addressed by #239 . Just need a rc14 release.

@rototor
Copy link
Contributor

rototor commented Jul 7, 2018

@koan00 You can manually reference pdfbox in your pom.xml and require 2.0.11 as a quick workaround. Just don't forget to remove or upgrade this reference in your pom.xml as soon as you upgrade this library.

If you can control all the fonts which are used to generate reports with this libary, you should not be affected. You are only in danger if you allow your users to supply their own html, in which they reference AFM fonts somehow. But I would not even know how to use some other fonts than .ttf with this library ...

@danfickle
Copy link
Owner

Thanks guys,
I just released RC-14.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants