Vulnerability Description
A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22 or later.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tika | >= 1.7, <= 1.21 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/39723d8227b248781898c200aa24b154683673287b1
- https://lists.apache.org/thread.html/da9ee189d1756f8508d0f2386d8e25aca5a6df54173
- https://lists.apache.org/thread.html/fb6c84fd387de997e5e366d50b0ca331a328c466432
- https://lists.apache.org/thread.html/fe876a649d9d36525dd097fe87ff4dcb3b82bb0fbb3
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133dee
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://lists.apache.org/thread.html/39723d8227b248781898c200aa24b154683673287b1
- https://lists.apache.org/thread.html/da9ee189d1756f8508d0f2386d8e25aca5a6df54173
- https://lists.apache.org/thread.html/fb6c84fd387de997e5e366d50b0ca331a328c466432
- https://lists.apache.org/thread.html/fe876a649d9d36525dd097fe87ff4dcb3b82bb0fbb3
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133dee
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
FAQ
What is CVE-2019-10094?
CVE-2019-10094 is a vulnerability with a CVSS score of 7.8 (HIGH). A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. A...
How severe is CVE-2019-10094?
CVE-2019-10094 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10094?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tika.