Apache has issued an advisory today (June 29): http://openwall.com/lists/oss-security/2018/06/29/1 The issue is fixed upstream in 1.8.14. Mageia 5 and Mageia 6 are also affected.
Whiteboard: (none) => MGA6TOOStatus comment: (none) => Fixed upstream in 1.8.14
Updated advisory with references: http://openwall.com/lists/oss-security/2018/06/29/2
openSUSE has issued an advisory for this today (September 7): https://lists.opensuse.org/opensuse-updates/2018-09/msg00028.html
Apache has issued an advisory today (October 5): https://www.openwall.com/lists/oss-security/2018/10/05/4 The issue is fixed upstream in 1.8.16 and 2.0.12.
Summary: pdfbox new security issue CVE-2018-8036 => pdfbox new security issues CVE-2018-8036 and CVE-2018-11797Source RPM: pdfbox-1.8.13-1.mga7.src.rpm => pdfbox-2.0.9-2.mga7.src.rpmStatus comment: Fixed upstream in 1.8.14 => Fixed upstream in 1.8.16 and 2.0.12
openSUSE has issued an advisory for this today (October 24): https://lists.opensuse.org/opensuse-updates/2018-10/msg00157.html
Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO
Fedora has issued an advisory for this on September 9: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/ It adds one new CVE, fixed upstream in 2.0.16. Again this was fixed in Cauldron with the CVEs in the commit message, but no bug for the new CVE.
Whiteboard: MGA7TOO, MGA6TOO => (none)Status comment: Fixed upstream in 1.8.16 and 2.0.12 => Fixed upstream in 2.0.16Version: Cauldron => 7CC: (none) => geiger.david68210Summary: pdfbox new security issues CVE-2018-8036 and CVE-2018-11797 => pdfbox new security issues CVE-2018-8036, CVE-2018-11797, and CVE-2019-0228
CVE: (none) => CVE-2019-0228CC: (none) => zombie_ryushu
Depends on: (none) => 28682
Depends on: (none) => 28708
Depends on: 28682 => (none)
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/
Resolution: (none) => OLDStatus: NEW => RESOLVED