Infinite loop in Apache Tika - CVE-2018-17197

 

Infinite loop in Apache Tika - CVE-2018-17197

Published: December 22, 2018 / Updated: December 24, 2018


Vulnerability identifier: #VU16676
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17197
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to an infinite loop when handling malicious input. A remote attacker can supply a carefully crafted or corrupt sqlite file, trigger and an infinite loop in Apache Tika's SQLite3Parser and cause the service to crash.


Affected software

Apache Tika
Oracle Communications Instant Messaging Server
Oracle Knowledge
Oracle FLEXCUBE Private Banking
Primavera Unifier

How to mitigate CVE-2018-17197

Update to version 1.20 or later.

Apache Tika - update to 1.20

External References

Related Security Bulletins