Описание
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
Ссылки
- Mailing ListVendor Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Mailing ListVendor Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.25 (включая)
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*
Конфигурация 2Версия от 17.7 (включая) до 17.12 (включая)
Одно из
cpe:2.3:a:oracle:healthcare_foundation:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:healthcare_foundation:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:healthcare_foundation:8.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*
EPSS
Процентиль: 40%
0.00177
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-835
CWE-835
Связанные уязвимости
CVSS3: 5.5
ubuntu
почти 5 лет назад
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
CVSS3: 5.5
redhat
почти 5 лет назад
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
CVSS3: 5.5
debian
почти 5 лет назад
A carefully crafted or corrupt file may trigger an infinite loop in Ti ...
EPSS
Процентиль: 40%
0.00177
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-835
CWE-835