Vulnerability Name: | CVE-2019-10088 (CCN-164709) | ||||||||||||||||||||||||||||||||
Assigned: | 2019-08-02 | ||||||||||||||||||||||||||||||||
Published: | 2019-08-02 | ||||||||||||||||||||||||||||||||
Updated: | 2020-08-24 | ||||||||||||||||||||||||||||||||
Summary: | A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-770 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-10088 Source: XF Type: UNKNOWN apache-cve201910088-dos(164709) Source: CONFIRM Type: Mailing List, Vendor Advisory https://lists.apache.org/thread.html/1c63555609b737c20d1bbfa4a3e73ec488e3408a84e2f5e47e1b7e08@%3Cdev.tika.apache.org%3E Source: MLIST Type: UNKNOWN [tika-dev] 20190813 Re: security fixes for CVE-2019-10088 and CVE-2019-1009{3,4} Source: MLIST Type: UNKNOWN [tika-dev] 20190812 Re: security fixes for CVE-2019-10088 and CVE-2019-1009{3,4} Source: MLIST Type: Mailing List, Patch, Vendor Advisory [tika-dev] 20190809 security fixes for CVE-2019-10088 and CVE-2019-1009{3,4} Source: MLIST Type: UNKNOWN [lucene-solr-user] 20200320 CVEs (vulnerabilities) that apply to Solr 8.4.1 Source: CCN Type: oss-sec Mailing List, Fri, 2 Aug 2019 07:33:38 -0400 [CVE-2019-10088] OOM from a crafted Zip File in Apache Tika's RecursiveParserWrapper Source: CONFIRM Type: UNKNOWN https://security.netapp.com/advisory/ntap-20190828-0004/ Source: CCN Type: Apache Tika Web site Apache Tika Source: CCN Type: IBM Security Bulletin 6444033 (Log Analysis) Multiple vulnerabilities in Apache Tika affects Apache Solr shipped with IBM Operations Analytics - Log Analysis Source: CCN Type: IBM Security Bulletin 6524700 (Planning Analytics Workspace) IBM Planning Analytics Workspace is affected by security vulnerabilities Source: CCN Type: Oracle CPUApr2020 Oracle Critical Patch Update Advisory - April 2020 Source: N/A Type: UNKNOWN N/A Source: CCN Type: Oracle CPUJan2020 Oracle Critical Patch Update Advisory - January 2020 Source: MISC Type: UNKNOWN https://www.oracle.com/security-alerts/cpujan2020.html | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |