PT-2019-4679 · Apache+1 · Apache Tika+1

Publicado

2019-08-02

·

Atualizado

2020-08-24

·

CVE-2019-10094

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Tika versions 1.7 through 1.21
Description A carefully crafted package or compressed file that yields the same file when unzipped or uncompressed can cause a StackOverflowError in the RecursiveParserWrapper. This issue is related to a buffer overflow in memory, which can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Apache Tika versions 1.7 through 1.21, upgrade to version 1.22 or later to resolve the issue.

Correção

Allocation of Resources Without Limits

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-01011
CVE-2019-10094
GHSA-MM7M-XG4H-6M52
SUSE-SU-2019:2521-1
SUSE-SU-2019:2930-1

Produtos afetados

Apache Tika
Suse