Vulnerability Name: | CVE-2019-10094 (CCN-164711) | ||||||||||||||||||||||||||||||||
Assigned: | 2019-08-02 | ||||||||||||||||||||||||||||||||
Published: | 2019-08-02 | ||||||||||||||||||||||||||||||||
Updated: | 2020-08-24 | ||||||||||||||||||||||||||||||||
Summary: | A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22 or later. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-770 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-10094 Source: XF Type: UNKNOWN apache-cve201910094-bo(164711) Source: MLIST Type: UNKNOWN [tika-dev] 20190813 Re: security fixes for CVE-2019-10088 and CVE-2019-1009{3,4} Source: MLIST Type: UNKNOWN [tika-dev] 20190812 Re: security fixes for CVE-2019-10088 and CVE-2019-1009{3,4} Source: MLIST Type: Mailing List, Vendor Advisory [tika-dev] 20190809 security fixes for CVE-2019-10088 and CVE-2019-1009{3,4} Source: CONFIRM Type: Mailing List, Vendor Advisory https://lists.apache.org/thread.html/fe876a649d9d36525dd097fe87ff4dcb3b82bb0fbb3a3d71fb72ef61@%3Cdev.tika.apache.org%3E Source: MLIST Type: UNKNOWN [lucene-solr-user] 20200320 CVEs (vulnerabilities) that apply to Solr 8.4.1 Source: CCN Type: oss-sec Mailing List, Fri, 2 Aug 2019 07:35:09 -0400 [CVE-2019-10094] StackOverflow from Crafted Package/Compressed Files in Apache Tika's RecursiveParserWrapper Source: CCN Type: Apache Tika Web site Apache Tika Source: CCN Type: IBM Security Bulletin 6444033 (Log Analysis) Multiple vulnerabilities in Apache Tika affects Apache Solr shipped with IBM Operations Analytics - Log Analysis Source: CCN Type: IBM Security Bulletin 6495351 (Log Analysis) Apache Solr, shipped with IBM Operations Analytics - Log Analysis, susceptible to multiple vulnerabilities in Apache Tika Source: CCN Type: IBM Security Bulletin 6524700 (Planning Analytics Workspace) IBM Planning Analytics Workspace is affected by security vulnerabilities Source: N/A Type: UNKNOWN N/A Source: MISC Type: UNKNOWN https://www.oracle.com/security-alerts/cpujan2020.html | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |