mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 06:52:09 +02:00
31 lines
1.2 KiB
Markdown
31 lines
1.2 KiB
Markdown
### [CVE-2018-8036](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8036)
|
|

|
|

|
|
%20Vulnerability&color=brighgreen)
|
|
|
|
### Description
|
|
|
|
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.oracle.com/security-alerts/cpuapr2020.html
|
|
|
|
#### Github
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/Anonymous-Phunter/PHunter
|
|
- https://github.com/CGCL-codes/PHunter
|
|
- https://github.com/DennisFeldbusch/Fuzz
|
|
- https://github.com/GCFuzzer/SP2023
|
|
- https://github.com/LibHunter/LibHunter
|
|
- https://github.com/hwen020/JQF
|
|
- https://github.com/jyi/JQF
|
|
- https://github.com/mfatima1/CS182
|
|
- https://github.com/moudemans/GFuzz
|
|
- https://github.com/olli22221/jqf
|
|
- https://github.com/qibowen-99/JQF_TEST
|
|
- https://github.com/rohanpadhye/JQF
|
|
- https://github.com/sarahc7/jqf-gson
|
|
|