tika-core: Denial of Service Vulnerabilities in Some of Apache Tika's Parsers
Published Apr 27, 2020
5.5
MEDIUMCVSS 3.1
EPSS 2.61%
Description
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser were partially fixed by upgrading the com.googlecode:isoparser:1.1.22 dependency to org.tallison:isoparser:1.9.41.2. For unrelated security reasons, we upgraded org.apache.cxf to 3.3.6 as part of the 1.24.1 release.
Affected products
-
- Version Up to 1.24StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Apache Software Foundation | Apache Tika | n/a |
|
Configuration 2
- 12.0.0
- 12.1.0
- ≥ 17.7 · ≤ 17.12
- 16.1
- 16.2
- 18.8
- 19.12
- 12.2.1.3.0
- 12.2.1.4.0
- 8.1
No data.
Red Hat Fuse 7.8.0
camel-tika
Fixed · RHSA-2020:5568
Red Hat JBoss BRMS 5
tika-core
Out of support scope
Red Hat JBoss BRMS 6
tika-core
Out of support scope
Red Hat JBoss Data Virtualization 6
tika-core
Out of support scope
Red Hat JBoss Fuse Service Works 6
tika-core
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.8.0 | camel-tika | Fixed | RHSA-2020:5568 |
| Red Hat JBoss BRMS 5 | tika-core | Out of support scope | n/a |
| Red Hat JBoss BRMS 6 | tika-core | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | tika-core | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | tika-core | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2020-9489 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1850042 Issue Tracking
- https://github.com/advisories/GHSA-4pv3-63jw-4jw2 Advisory
- https://github.com/apache/tika/commit/0f4d5de0f85455e91433fb0b464ea0461d7c891d
- https://issues.apache.org/jira/browse/TIKA-3081
- https://lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b%40%3Cnotifications.james.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b@%3Cnotifications.james.apache.org%3E
- https://lists.apache.org/thread.html/r4d943777e36ca3aa6305a45da5acccc54ad894f2d5a07186cfa2442c%40%3Cdev.tika.apache.org%3E x_refsource_MISCMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-9489
- https://www.cve.org/CVERecord?id=CVE-2020-9489
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.