oss-sec mailing list archives
[CVE-2018-8017] Apache Tika Denial of Service Vulnerability -- Potential Infinite Loop in IptcAnpaParser
From: Tim Allison <tallison () apache org>
Date: Wed, 19 Sep 2018 08:49:50 -0400
CVE-2018-8017: Apache Tika Denial of Service Vulnerability -- Potential Infinite Loop in IptcAnpaParser Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Tika 1.2 to 1.18 Description: A carefully crafted file can trigger an infinite loop in Apache Tika's IptcAnpaParser. Mitigation: Apache Tika users should upgrade to 1.19 or later. Credit: This issue was discovered by Tobias Ospelt of modzero AG.
Current thread:
- [CVE-2018-8017] Apache Tika Denial of Service Vulnerability -- Potential Infinite Loop in IptcAnpaParser Tim Allison (Sep 19)