PT-2019-4679 · Apache+1 · Apache Tika+1

Published

2019-08-02

·

Updated

2020-08-24

·

CVE-2019-10094

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Tika versions 1.7 through 1.21
Description A carefully crafted package or compressed file that yields the same file when unzipped or uncompressed can cause a StackOverflowError in the RecursiveParserWrapper. This issue is related to a buffer overflow in memory, which can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Apache Tika versions 1.7 through 1.21, upgrade to version 1.22 or later to resolve the issue.

Fix

Allocation of Resources Without Limits

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01011
CVE-2019-10094
GHSA-MM7M-XG4H-6M52
SUSE-SU-2019:2521-1
SUSE-SU-2019:2930-1

Affected Products

Apache Tika
Suse