PT-2021-17887 · Apache+2 · Apache Tika+2

Published

2021-03-31

·

Updated

2022-05-10

·

CVE-2021-28657

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Apache Tika versions up to and including 1.25
Description: A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser. Users should upgrade to a newer version to resolve the issue.
Recommendations: For versions up to and including 1.25, upgrade to 1.26 or later.

Fix

Infinite Loop

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28657
GHSA-567X-M4WM-87V8
SUSE-SU-2021:2098-1
SUSE-SU-2021:2114-1

Affected Products

Apache Tika
Debian
Suse