First published: Wed Sep 19 2018(Updated: )
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tika | >=1.2<=1.18 | |
maven/org.apache.tika:tika-core | >=1.2<1.19 | 1.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8017 is a vulnerability in Apache Tika versions 1.2 to 1.18 that can be exploited by a carefully crafted file to trigger an infinite loop in the IptcAnpaParser.
CVE-2018-8017 has a severity rating of medium with a CVSS score of 5.5.
CVE-2018-8017 can be exploited by using a specially crafted file to trigger an infinite loop in the IptcAnpaParser component of Apache Tika.
Apache Tika versions 1.2 to 1.18 are affected by CVE-2018-8017.
To fix CVE-2018-8017, it is recommended to update Apache Tika to a version higher than 1.18 where the vulnerability has been patched.