Bug 29125 - pdfbox new security issues CVE-2021-3181[12]
Summary: pdfbox new security issues CVE-2021-3181[12]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 28708
  Show dependency treegraph
 
Reported: 2021-06-13 23:43 CEST by David Walser
Modified: 2021-07-27 22:23 CEST (History)
5 users (show)

See Also:
Source RPM: pdfbox-2.0.23-1.mga9.src.rpm
CVE: CVE-2021-3181[12]
Status comment:


Attachments

Description David Walser 2021-06-13 23:43:37 CEST
Apache has issued advisories on June 12:
https://www.openwall.com/lists/oss-security/2021/06/12/2
https://www.openwall.com/lists/oss-security/2021/06/12/1

The issues are fixed upstream in 2.0.24.

Mageia 7 and Mageia 8 are also affected.
David Walser 2021-06-13 23:44:13 CEST

Whiteboard: (none) => MGA8TOO, MGA7TOO
Blocks: (none) => 28708
Status comment: (none) => Fixed upstream in 2.0.24

Comment 1 David Walser 2021-06-25 00:41:54 CEST
Fedora has issued an advisory for this today (June 24):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MDJKJQOMVFDFIDS27OQJXNOYHV2O273D/
Comment 2 David Walser 2021-07-01 18:57:18 CEST
Removing Mageia 7 from whiteboard due to EOL:
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Whiteboard: MGA8TOO, MGA7TOO => MGA8TOO

Comment 3 Nicolas Lécureuil 2021-07-23 17:37:05 CEST
new version pushed in mga8/9


src:
    - pdfbox-2.0.24-1.mga8

Assignee: java => qa-bugs
CC: (none) => mageia
Status comment: Fixed upstream in 2.0.24 => (none)

Comment 4 David Walser 2021-07-23 17:53:10 CEST
pdfbox-2.0.24-1.mga8
pdfbox-debugger-2.0.24-1.mga8
fontbox-2.0.24-1.mga8
preflight-2.0.24-1.mga8
xmpbox-2.0.24-1.mga8
pdfbox-tools-2.0.24-1.mga8
pdfbox-parent-2.0.24-1.mga8
pdfbox-reactor-2.0.24-1.mga8
pdfbox-javadoc-2.0.24-1.mga8

from pdfbox-2.0.24-1.mga8.src.rpm

Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)

Comment 5 Aurelien Oudelet 2021-07-23 22:47:51 CEST
Advisory:
========================

In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions (CVE-2021-31811).

In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions (CVE-2021-31812).

References:
 - https://bugs.mageia.org/show_bug.cgi?id=29125
 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31811
 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31812
 - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MDJKJQOMVFDFIDS27OQJXNOYHV2O273D/
========================

Updated packages in core/updates_testing:
========================
pdfbox-2.0.24-1.mga8
pdfbox-debugger-2.0.24-1.mga8
fontbox-2.0.24-1.mga8
preflight-2.0.24-1.mga8
xmpbox-2.0.24-1.mga8
pdfbox-tools-2.0.24-1.mga8
pdfbox-parent-2.0.24-1.mga8
pdfbox-reactor-2.0.24-1.mga8
pdfbox-javadoc-2.0.24-1.mga8

from pdfbox-2.0.24-1.mga8.src.rpm

CC: (none) => ouaurelien

Comment 6 Herman Viaene 2021-07-26 15:49:18 CEST
MGA8-64 Plasma on Lenovo B50
No installation issues.
Ref bug 28682 where our boss recommends OK on clean install. I won't contradict him.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 7 Thomas Andrews 2021-07-27 03:48:34 CEST
Good to know there's no dissension in the ranks.

Validating. Advisory in Comment 5.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Aurelien Oudelet 2021-07-27 20:47:42 CEST

Keywords: (none) => advisory
CVE: (none) => CVE-2021-3181[12]

Comment 8 Mageia Robot 2021-07-27 22:23:29 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0378.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.