PT-2020-4628 · Apache+1 · Apache Tika+1

Published

2020-04-24

·

Updated

2022-10-07

·

CVE-2020-9489

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Tika versions prior to 1.24.1
Description A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser, and ImageParser. The issue is related to memory release errors before the last reference is deleted, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For versions prior to 1.24.1, upgrade to 1.24.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable parsers, such as OneNoteParser, ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, and ImageParser, until the upgrade is applied.

Fix

Infinite Loop

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2020-05177
CVE-2020-9489
GHSA-4PV3-63JW-4JW2

Affected Products

Apache Tika
Debian