First published: Wed Apr 25 2018(Updated: )
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tika | <1.18 | |
redhat/tika | <1.18 | 1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1339 is medium with a severity value of 5.5.
Versions of Apache Tika before 1.18 are affected by CVE-2018-1339.
A carefully crafted file can trigger an infinite loop by exploiting a vulnerability in Apache Tika's ChmParser component.
Yes, updating Apache Tika to version 1.18 or later will remedy the vulnerability.
Yes, you can find references for CVE-2018-1339 at the following links: [link1], [link2], [link3].