Vulnerability Description
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nutch | 2.3.1 |
| Apache | Tika | <= 1.13 |
Related Weaknesses (CWE)
References
- http://seclists.org/bugtraq/2016/Nov/40Mailing ListThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/94247Third Party AdvisoryVDB Entry
- https://dist.apache.org/repos/dist/release/tika/CHANGES-1.14.txtRelease NotesVendor Advisory
- https://lists.apache.org/thread.html/91eb639ef619b9a26b40020ca6732e7dbe457f7322e
- https://lists.apache.org/thread.html/d2375da29d89e679abf5d845db76d6f798fdc6f7d44
- https://lists.apache.org/thread.html/e414754a6c57ce7194b731e211cd6b2cbb41f2c7000
- https://lists.apache.org/thread.html/r2f6f6c130b12b7332f323f74d031072b1517065ce2
- https://lists.apache.org/thread.html/rfd3646bb724b66b1a9ddef69e692da2b7a727a8799
- http://seclists.org/bugtraq/2016/Nov/40Mailing ListThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/94247Third Party AdvisoryVDB Entry
- https://dist.apache.org/repos/dist/release/tika/CHANGES-1.14.txtRelease NotesVendor Advisory
- https://lists.apache.org/thread.html/91eb639ef619b9a26b40020ca6732e7dbe457f7322e
- https://lists.apache.org/thread.html/d2375da29d89e679abf5d845db76d6f798fdc6f7d44
- https://lists.apache.org/thread.html/e414754a6c57ce7194b731e211cd6b2cbb41f2c7000
- https://lists.apache.org/thread.html/r2f6f6c130b12b7332f323f74d031072b1517065ce2
FAQ
What is CVE-2016-6809?
CVE-2016-6809 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
How severe is CVE-2016-6809?
CVE-2016-6809 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-6809?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Nutch, Apache Tika.