CVE-2018-8017: Medium severity apache tika vulnerability
Published Sep 19, 2018
·Updated
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
Affected Software
2 affected componentsFixes available
Apache Tika>=1.2<=1.18
maven/org.apache.tika:tika-core>=1.2<1.19
1.19
Event History
Sep 19, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Oct 17, 2018
Advisory Published
via GitHub·03:50 PM
Frequently Asked Questions
1
What is CVE-2018-8017?
CVE-2018-8017 is a vulnerability in Apache Tika versions 1.2 to 1.18 that can be exploited by a carefully crafted file to trigger an infinite loop in the IptcAnpaParser.
2
How severe is CVE-2018-8017?
CVE-2018-8017 has a severity rating of medium with a CVSS score of 5.5.
3
How can CVE-2018-8017 be exploited?
CVE-2018-8017 can be exploited by using a specially crafted file to trigger an infinite loop in the IptcAnpaParser component of Apache Tika.
4
Which version of Apache Tika is affected by CVE-2018-8017?
Apache Tika versions 1.2 to 1.18 are affected by CVE-2018-8017.
5
How can I fix CVE-2018-8017?
To fix CVE-2018-8017, it is recommended to update Apache Tika to a version higher than 1.18 where the vulnerability has been patched.