First published: Wed Apr 25 2018(Updated: )
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tika | <1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1338 is medium with a CVSS score of 5.5.
A carefully crafted file can trigger an infinite loop in Apache Tika's BPGParser by exploiting a vulnerability in versions of Apache Tika before 1.18.
The Apache Tika software is affected by CVE-2018-1338 in versions before 1.18.
To fix CVE-2018-1338, update Apache Tika to version 1.18 or later.
You can find more information about CVE-2018-1338 at the following references: [Link 1](https://lists.apache.org/thread.html/4d20c5748fb9f836653bc78a1bad991ba8485d82a1e821f70b641932@%3Cdev.tika.apache.org%3E), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1572423), [Link 3](https://access.redhat.com/security/updates/classification/).