First published: Mon May 16 2022(Updated: )
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tika | <1.28.2 | |
Apache Tika | >=2.0.0<2.4.0 | |
Oracle Primavera Unifier | >=17.7<=17.12 | |
Oracle Primavera Unifier | =18.8 | |
Oracle Primavera Unifier | =19.12 | |
Oracle Primavera Unifier | =20.12 | |
Oracle Primavera Unifier | =21.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25169 is a vulnerability in the BPG parser in Apache Tika before versions 1.28.2 and 2.4.0.
CVE-2022-25169 has a severity level of medium with a CVSS score of 5.5.
Versions before 1.28.2 of Apache Tika and versions before 2.4.0 of Apache Tika are affected. Oracle Primavera Unifier versions 17.7 to 17.12, 18.8, 19.12, 20.12, and 21.12 are also affected.
CVE-2022-25169 may allow an attacker to allocate an unreasonable amount of memory on carefully crafted files, leading to a denial-of-service condition.
Yes, you can find more information about CVE-2022-25169 in the following references: - [Openwall](http://www.openwall.com/lists/oss-security/2022/05/16/4) - [Apache Tika mailing list](https://lists.apache.org/thread/t3tb51sf0k2pmbnzsrrrm23z9r1c10rk) - [NetApp advisory](https://security.netapp.com/advisory/ntap-20220804-0004/)