REDHAT-BUG-1850042: Medium severity Apache Tika vulnerability
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser.
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-9489 http://seclists.org/oss-sec/2020/q2/69 https://lists.apache.org/thread.html/r4d943777e36ca3aa6305a45da5acccc54ad894f2d5a07186cfa2442c%40%3Cdev.tika.apache.org%3E
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1850042?
The severity level of REDHAT-BUG-1850042 has not been publicly disclosed but involves potential out of memory errors and infinite loops.
How do I fix REDHAT-BUG-1850042?
To mitigate REDHAT-BUG-1850042, it's recommended to update Apache Tika to the latest version that addresses this vulnerability.
What are the potential impacts of REDHAT-BUG-1850042?
Potential impacts of REDHAT-BUG-1850042 include application crashes, out of memory errors, and performance degradation due to infinite loops.
Which versions of Apache Tika are affected by REDHAT-BUG-1850042?
REDHAT-BUG-1850042 affects various versions of Apache Tika specifically involving its OneNote Parser and other parsers like ICNS, MP3, MP4, SAS7BDAT, and ImageParser.
Is REDHAT-BUG-1850042 being actively addressed?
Yes, REDHAT-BUG-1850042 is being addressed with updates from the Apache Tika development team.