CVE-2018-11762
published 2018-09-19CVE-2018-11762: In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has…
PriorityP432medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
5.45%
91.8th percentile
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| apache | tika | >= 0 < 1.20-1 | 1.20-1 |
| apache | tika | 0.9 – 1.18 | — |
| apache_software_foundation | apache_tika | — | — |
| debian | tika | < tika 1.20-1 (bullseye) | tika 1.20-1 (bullseye) |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.9MEDIUM
vendor_apache5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tika: Zip Slip vulnerability in tika-app
vendor_redhat·2018-09-19·CVSS 5.9
CVE-2018-11762 [MEDIUM] CWE-20 tika: Zip Slip vulnerability in tika-app
tika: Zip Slip vulnerability in tika-app
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
Package: tika-core (Red Hat BPM Suite 6) - Will not fix
Package: camel-tika (Red Hat Fuse 7) - Not affected
Package: tika-core (Red Hat JBoss BRMS 5) - Not affected
Package: tika-core (Red Hat JBoss BRMS 6) - Will not fix
Package: tika-core (Red Hat JBoss Data Virtualization 6) - Will not fix
Package: tika-core (Red Hat JBoss Fuse Integration Service 2) - Out of support scope
Package: tika-core (Red Hat JBoss Fuse Service Works 6) - Will not fix
Package: tika (Red Hat Satellite 5) - Not a
Debian
CVE-2018-11762: tika - In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an...
vendor_debian·2018·CVSS 5.9
CVE-2018-11762 [MEDIUM] CVE-2018-11762: tika - In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an...
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
Scope: local
bullseye: resolved (fixed in 1.20-1)
sid: resolved (fixed in 1.20-1)
Apache
Apache tika: CVE-2018-11762
vendor_apache·CVSS 5.9
CVE-2018-11762 [MEDIUM] Apache tika: CVE-2018-11762
Apache tika: CVE-2018-11762
Rare Zip Slip Vulnerability in tika-app Tim Allison 0.9-1.18 RIFFReader Infinite Loop in AudioParser in Java 8 and 9 Sergey Bylokhov and Tobias Ospelt ?-1.18 TIKA-2446 OOM detecting OPCPackage files with corrupt ZIP Thorsten Schäfer ?-1.18 PDFBOX-4014 Infinite loop in JBig2 (versions less than 3.0.0) Hanno Böck (if user supplied) ?-1.17
GHSA
Moderate severity vulnerability that affects org.apache.tika:tika-core
ghsa·2018-10-17
CVE-2018-11762 [MEDIUM] CWE-22 Moderate severity vulnerability that affects org.apache.tika:tika-core
Moderate severity vulnerability that affects org.apache.tika:tika-core
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
OSV
Moderate severity vulnerability that affects org.apache.tika:tika-core
osv·2018-10-17
CVE-2018-11762 [MEDIUM] Moderate severity vulnerability that affects org.apache.tika:tika-core
Moderate severity vulnerability that affects org.apache.tika:tika-core
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
OSV
CVE-2018-11762: In Apache Tika 0
osv·2018-09-19·CVSS 5.9
CVE-2018-11762 [MEDIUM] CVE-2018-11762: In Apache Tika 0
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11762 tika: Zip Slip vulnerability in tika-app
bugzilla·2018-09-24·CVSS 5.9
CVE-2018-11762 [MEDIUM] CVE-2018-11762 tika: Zip Slip vulnerability in tika-app
CVE-2018-11762 tika: Zip Slip vulnerability in tika-app
A flaw was found in Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
References:
https://lists.apache.org/thread.html/ab2e1af38975f5fc462ba89b517971ef892ec3d06bee12ea2258895b@%3Cdev.tika.apache.org%3E
https://seclists.org/oss-sec/2018/q3/256
Discussion:
Created tika tracking bugs for this issue:
Affects: fedora-all [bug 1632470]
---
Upstream bug:
https://issues.apache.org/jira/browse/TIKA-2687
Upstream commits:
https://github.com/apache/tika/commit/a09d853dbed712f644e274b497cce254f3189d57
https://github.com/apache/tika/com
Bugzilla
CVE-2018-11762 tika: Zip Slip vulnerability in tika-app [fedora-all]
bugzilla·2018-09-24·CVSS 5.9
CVE-2018-11762 [MEDIUM] CVE-2018-11762 tika: Zip Slip vulnerability in tika-app [fedora-all]
CVE-2018-11762 tika: Zip Slip vulnerability in tika-app [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
http://www.securityfocus.com/bid/105515https://lists.apache.org/thread.html/ab2e1af38975f5fc462ba89b517971ef892ec3d06bee12ea2258895b%40%3Cdev.tika.apache.org%3Ehttp://www.securityfocus.com/bid/105515https://lists.apache.org/thread.html/ab2e1af38975f5fc462ba89b517971ef892ec3d06bee12ea2258895b%40%3Cdev.tika.apache.org%3E
2018-09-19
Published