CVE-2018-8017
published 2018-09-19CVE-2018-8017: In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
PriorityP421medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
2.51%
83.0th percentile
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| apache | tika | >= 0 < 1.20-1 | 1.20-1 |
| apache | tika | 1.2 – 1.18 | — |
| apache_software_foundation | apache_tika | — | — |
| debian | tika | < tika 1.20-1 (bullseye) | tika 1.20-1 (bullseye) |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_apache5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tika: infinite loop in the IptcAnpaParser
vendor_redhat·2018-09-19·CVSS 5.5
CVE-2018-8017 [MEDIUM] CWE-835 tika: infinite loop in the IptcAnpaParser
tika: infinite loop in the IptcAnpaParser
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
Package: tika-core (Red Hat BPM Suite 6) - Will not fix
Package: camel-tika (Red Hat Fuse 7) - Not affected
Package: tika-core (Red Hat JBoss BRMS 5) - Will not fix
Package: tika-core (Red Hat JBoss BRMS 6) - Will not fix
Package: tika-core (Red Hat JBoss Data Virtualization 6) - Will not fix
Package: tika-core (Red Hat JBoss Fuse Integration Service 2) - Out of support scope
Package: tika-core (Red Hat JBoss Fuse Service Works 6) - Will not fix
Package: tika (Red Hat Satellite 5) - Not affected
Package: rh-eclipse46-tika (Red Hat Software Collections) - Will not fix
Debian
CVE-2018-8017: tika - In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loo...
vendor_debian·2018·CVSS 5.5
CVE-2018-8017 [MEDIUM] CVE-2018-8017: tika - In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loo...
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
Scope: local
bullseye: resolved (fixed in 1.20-1)
sid: resolved (fixed in 1.20-1)
Apache
Apache tika: CVE-2018-8017
vendor_apache·CVSS 5.5
CVE-2018-8017 [MEDIUM] Apache tika: CVE-2018-8017
Apache tika: CVE-2018-8017
Infinite Loop in IptcAnpaParser Rohan Padhye and Tobias Ospelt 1.2-1.18
OSV
Comparison errorr in org.apache.tika:tika-core
osv·2018-10-17
CVE-2018-8017 [MEDIUM] Comparison errorr in org.apache.tika:tika-core
Comparison errorr in org.apache.tika:tika-core
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
GHSA
Comparison errorr in org.apache.tika:tika-core
ghsa·2018-10-17
CVE-2018-8017 [MEDIUM] CWE-835 Comparison errorr in org.apache.tika:tika-core
Comparison errorr in org.apache.tika:tika-core
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
OSV
CVE-2018-8017: In Apache Tika 1
osv·2018-09-19·CVSS 5.5
CVE-2018-8017 [MEDIUM] CVE-2018-8017: In Apache Tika 1
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-8017 tika: infinite loop in the IptcAnpaParser
bugzilla·2018-09-24·CVSS 5.5
CVE-2018-8017 [MEDIUM] CVE-2018-8017 tika: infinite loop in the IptcAnpaParser
CVE-2018-8017 tika: infinite loop in the IptcAnpaParser
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
References:
https://lists.apache.org/thread.html/72df7a3f0dda49a912143a1404b489837a11f374dfd1961061873a91@%3Cdev.tika.apache.org%3E
Discussion:
Created tika tracking bugs for this issue:
Affects: fedora-all [bug 1632467]
---
Upstream commit:
https://github.com/apache/tika/commit/62926cae31a02d4f23d21148435804b96c543cc7
---
Some more details can be found in:
https://www.modzero.ch/modlog/archives/2018/09/20/java_bugs_with_and_without_fuzzing/index.html
with test case available at:
https://github.com/modzero/mod0javaFuzzingResults/blob/master/12_hang_tika_iptc.iptc
---
RHN Satellite 5 is shipped with an older version
Bugzilla
CVE-2018-8017 tika: infinite loop in the IptcAnpaParser [fedora-all]
bugzilla·2018-09-24·CVSS 5.5
CVE-2018-8017 [MEDIUM] CVE-2018-8017 tika: infinite loop in the IptcAnpaParser [fedora-all]
CVE-2018-8017 tika: infinite loop in the IptcAnpaParser [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
http://www.securityfocus.com/bid/105513https://lists.apache.org/thread.html/72df7a3f0dda49a912143a1404b489837a11f374dfd1961061873a91%40%3Cdev.tika.apache.org%3Ehttp://www.securityfocus.com/bid/105513https://lists.apache.org/thread.html/72df7a3f0dda49a912143a1404b489837a11f374dfd1961061873a91%40%3Cdev.tika.apache.org%3E
2018-09-19
Published