Bug 28682 - pdfbox new security issues CVE-2021-27807 and CVE-2021-27906
Summary: pdfbox new security issues CVE-2021-27807 and CVE-2021-27906
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 28708
  Show dependency treegraph
 
Reported: 2021-03-30 23:25 CEST by David Walser
Modified: 2021-05-29 20:16 CEST (History)
4 users (show)

See Also:
Source RPM: pdfbox-2.0.21-2.mga8.src.rpm
CVE: CVE-2021-27807, CVE-2021-27906
Status comment:


Attachments

Description David Walser 2021-03-30 23:25:29 CEST
Apache has issued advisories on March 19:
https://www.openwall.com/lists/oss-security/2021/03/19/9
https://www.openwall.com/lists/oss-security/2021/03/19/10

The issues are fixed upstream in 2.0.23.

Mageia 7 is also affected (see also Bug 23251).
David Walser 2021-03-30 23:25:46 CEST

Version: Cauldron => 8
Whiteboard: (none) => MGA7TOO
Status comment: (none) => Fixed upstream in 2.0.23

David Walser 2021-03-30 23:27:13 CEST

Blocks: (none) => 23251

Nicolas Lécureuil 2021-04-03 00:26:21 CEST

Blocks: (none) => 28708

Comment 1 Nicolas Lécureuil 2021-04-03 00:27:57 CEST
fixed in mga8:

src:
    - pdfbox-2.0.23-1.mga8


bug cloned in 28708 for mga7

Whiteboard: MGA7TOO => (none)
Blocks: 23251, 28708 => (none)
CC: (none) => mageia

Nicolas Lécureuil 2021-04-03 00:28:13 CEST

Assignee: java => qa-bugs
Status comment: Fixed upstream in 2.0.23 => (none)

David Walser 2021-04-03 00:30:52 CEST

Blocks: (none) => 28708

Comment 2 David Walser 2021-04-04 17:50:12 CEST
Advisory:
========================

Updated pdfbox packages fix security vulnerabilities:

A carefully crafted PDF file can trigger an infinite loop while loading the
file. This issue affects Apache PDFBox Apache PDFBox version 2.0.22 and prior
2.0.x versions (CVE-2021-27807).

A carefully crafted PDF file can trigger an OutOfMemory-Exception while
loading the file. This issue affects Apache PDFBox Apache PDFBox version
2.0.22 and prior 2.0.x versions (CVE-2021-27906).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27807
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27906
https://www.openwall.com/lists/oss-security/2021/03/19/9
https://www.openwall.com/lists/oss-security/2021/03/19/10
========================

Updated packages in core/updates_testing:
========================
pdfbox-2.0.23-1.mga8
xmpbox-2.0.23-1.mga8
pdfbox-tools-2.0.23-1.mga8
pdfbox-parent-2.0.23-1.mga8
pdfbox-reactor-2.0.23-1.mga8
pdfbox-javadoc-2.0.23-1.mga8
pdfbox-debugger-2.0.23-1.mga8
fontbox-2.0.23-1.mga8
preflight-2.0.23-1.mga8

from pdfbox-2.0.23-1.mga8.src.rpm
Comment 3 Thomas Andrews 2021-04-07 15:57:41 CEST
Installed all packages, including numerous dependencies, in a vbox mga8 Plasma guest.

Referenced Bug 18558 for testing suggestions, where I read that QA had been advised to OK this on a clean install and update over the previous versions.

Updated using qarepo, with no issues, so it looks OK here. Validating. Advisory in Comment 2.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs

Aurelien Oudelet 2021-04-12 16:27:32 CEST

CC: (none) => ouaurelien
Keywords: (none) => advisory
CVE: (none) => CVE-2021-27807, CVE-2021-27906

Comment 4 Mageia Robot 2021-04-12 22:02:34 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0184.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 5 David Walser 2021-05-29 20:16:59 CEST
Fedora has issued an advisory for this on March 26:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6PT72QOFDXLJ7PLTN66EMG5EHPTE7TFZ/

Note You need to log in before you can comment on or make changes to this bug.