Описание
In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug is most likely denial-of-service against software that uses the ORC file parser. With the C++ parser, the stack overflow might possibly corrupt the stack.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.0.0 (исключая) до 1.4.3 (включая)
cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.04145
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-674
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Apache ORC vulnerable to Uncontrolled Recursion
EPSS
Процентиль: 88%
0.04145
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-674