CVE-2018-17197: SQL Injection
Published Dec 24, 2018
·Updated
A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.
Affected Software
2 affected componentsFixes available
maven/org.apache.tika:tika-parsers>=1.8<1.20
1.20
Apache Tika>=1.8<=1.19.1
Event History
Dec 24, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Dec 26, 2018
Advisory Published
05:45 PM
Frequently Asked Questions
1
What is CVE-2018-17197?
CVE-2018-17197 is a vulnerability that allows a carefully crafted or corrupt SQLite file to cause an infinite loop in Apache Tika's SQLite3Parser.
2
Which versions of Apache Tika are affected by CVE-2018-17197?
Versions 1.8 to 1.19.1 of Apache Tika are affected by CVE-2018-17197.
3
What is the severity of CVE-2018-17197?
The severity of CVE-2018-17197 is medium, with a severity value of 6.5.
4
How can I fix CVE-2018-17197?
To fix CVE-2018-17197, update your Apache Tika version to 1.20 or higher.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-17197?
The Common Weakness Enumeration (CWE) ID for CVE-2018-17197 is CWE-89 and CWE-835.