CVE-2018-8017

CWE-83510 documents8 sources
Severity
5.5MEDIUM
EPSS
2.1%
top 15.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateOct 17

Description

In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Mavenorg.apache.tika:tika-core1.21.19
NVDapache/tika1.21.18
Debiantika< 1.20-1

🔴Vulnerability Details

4
OSV
Comparison errorr in org.apache.tika:tika-core2018-10-17
GHSA
Comparison errorr in org.apache.tika:tika-core2018-10-17
OSV
CVE-2018-8017: In Apache Tika 12018-09-19
CVEList
CVE-2018-8017: In Apache Tika 12018-09-19

📋Vendor Advisories

3
Red Hat
tika: infinite loop in the IptcAnpaParser2018-09-19
Debian
CVE-2018-8017: tika - In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loo...2018
Apache
Apache tika: CVE-2018-8017

💬Community

2
Bugzilla
CVE-2018-8017 tika: infinite loop in the IptcAnpaParser2018-09-24
Bugzilla
CVE-2018-8017 tika: infinite loop in the IptcAnpaParser [fedora-all]2018-09-24
CVE-2018-8017 (MEDIUM CVSS 5.5) | In Apache Tika 1.2 to 1.18 | cvebase.io