[ 
https://issues.apache.org/jira/browse/PDFBOX-4347?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16658313#comment-16658313
 ] 

ASF subversion and git services commented on PDFBOX-4347:
---------------------------------------------------------

Commit 1844507 from til...@apache.org in branch 'pdfbox/branches/2.0'
[ https://svn.apache.org/r1844507 ]

PDFBOX-4347: don't set -1 if value is missing, this can result in an 
ArrayIndexOutOfBoundsException

> ArrayIndexOutOfBoundsException in PDFXrefStreamParser
> -----------------------------------------------------
>
>                 Key: PDFBOX-4347
>                 URL: https://issues.apache.org/jira/browse/PDFBOX-4347
>             Project: PDFBox
>          Issue Type: Bug
>          Components: Parsing
>            Reporter: Robin Schimpf
>            Assignee: Tilman Hausherr
>            Priority: Minor
>             Fix For: 2.0.13, 3.0.0 PDFBox
>
>         Attachments: ArrayIndexOutOfBoundsException PDFXrefStreamParser#parse
>
>
> Fuzzing PDF loading with [JQF|https://github.com/rohanpadhye/jqf] triggered 
> an ArrayIndexOutOfBoundsException.
> {code:java}
> java.lang.ArrayIndexOutOfBoundsException: 1
>       at 
> org.apache.pdfbox.pdfparser.PDFXrefStreamParser.parse(PDFXrefStreamParser.java:150)
>       at 
> org.apache.pdfbox.pdfparser.COSParser.parseXrefStream(COSParser.java:2767)
>       at 
> org.apache.pdfbox.pdfparser.COSParser.parseXrefObjStream(COSParser.java:442)
>       at org.apache.pdfbox.pdfparser.COSParser.parseXref(COSParser.java:392)
>       at 
> org.apache.pdfbox.pdfparser.COSParser.retrieveTrailer(COSParser.java:254)
>       at 
> org.apache.pdfbox.pdfparser.PDFParser.initialParse(PDFParser.java:171)
>       at org.apache.pdfbox.pdfparser.PDFParser.parse(PDFParser.java:220)
>       at org.apache.pdfbox.pdmodel.PDDocument.load(PDDocument.java:1160)
>       at org.apache.pdfbox.pdmodel.PDDocument.load(PDDocument.java:1057)
>     ...
> {code}
> The Code used for fuzzing is
> {code:java}
> PDDocument.load(inputStream)
> {code}



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@pdfbox.apache.org
For additional commands, e-mail: dev-h...@pdfbox.apache.org

Reply via email to