Описание
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| tika | unfixed | package | ||
| tika | no-dsa | bullseye | package | |
| tika | no-dsa | buster | package |
Примечания
https://www.openwall.com/lists/oss-security/2022/05/16/4
Связанные уязвимости
CVSS3: 5.5
ubuntu
больше 3 лет назад
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
CVSS3: 5.5
nvd
больше 3 лет назад
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
CVSS3: 5.5
github
больше 3 лет назад
Apache Tika vulnerable to uncontrolled memory consumption