tika-parsers is vulnerable to denial of service (DoS). The vulnerability exists through an infinite loop when parsing an MP3
lyrics with a tagLen
lesser than 1, or larger than the lyrics’ length.
CPE | Name | Operator | Version |
---|---|---|---|
apache tika parser modules | le | 1.25 | |
apache tika parser modules | le | 1.25 |
github.com/apache/tika/commit/26a9965659921a8aa4205393479584372db7cb35
lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b@%3Cnotifications.james.apache.org%3E
lists.apache.org/thread.html/r915add4aa52c60d1b5cf085039cfa73a98d7fae9673374dfd7744b5a%40%3Cdev.tika.apache.org%3E
security.netapp.com/advisory/ntap-20210507-0004/
www.openwall.com/lists/oss-security/2021/03/30/3
www.oracle.com/security-alerts/cpuapr2022.html
www.oracle.com/security-alerts/cpuoct2021.html