First published: Fri Aug 02 2019(Updated: )
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tika | >=1.7<=1.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2019-10088.
The severity of CVE-2019-10088 is high with a score of 8.8.
Apache Tika versions 1.7-1.21 are affected by CVE-2019-10088.
A carefully crafted or corrupt zip file can cause an Out-of-Memory (OOM) error in Apache Tika's RecursiveParserWrapper, leading to a denial of service.
Users should upgrade to Apache Tika version 1.22 or later to mitigate CVE-2019-10088.