cbcvebase.
CVE-2018-1339
published 2018-04-25

CVE-2018-1339: A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.

medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.

Affected

5 ranges
VendorProductVersion rangeFixed in
apachetika< 1.181.18
apachetika
apachetika>= 0 < 1.18-11.18-1
apache_software_foundationapache_tika< 1.181.18
debiantika< tika 1.18-1 (bullseye)tika 1.18-1 (bullseye)

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM