First published: Fri Aug 02 2019(Updated: )
A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22 or later.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tika | >=1.7<=1.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10094 is a vulnerability in Apache Tika that causes a StackOverflowError when unzipping a carefully crafted file that yields the same file (a quine).
To fix CVE-2019-10094, Apache Tika users should upgrade to version 1.22 or later.
CVE-2019-10094 has a severity of 7.8 (High).