First published: Wed Sep 19 2018(Updated: )
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tika | >=0.9<=1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11762 is medium, with a severity value of 5.9.
CVE-2018-11762 affects Apache Tika versions 0.9 to 1.18.
The impact of CVE-2018-11762 is that in a rare edge case, tika-app can overwrite a file if the user does not specify an extract directory on the command line and the input file has an embedded file with an absolute path.
To fix CVE-2018-11762, update Apache Tika to version 1.19 or later.
You can find more information about CVE-2018-11762 at the following references: [1] http://www.securityfocus.com/bid/105515 [2] https://lists.apache.org/thread.html/ab2e1af38975f5fc462ba89b517971ef892ec3d06bee12ea2258895b@%3Cdev.tika.apache.org%3E