Bugzilla – Bug 1193835
VUL-0: CVE-2018-1339: tika-core: Infinite loop in ChmParser can allow remote attacker to cause a denial of service
Last modified: 2021-12-16 15:53:49 UTC
rh#1572424 Apache Tika before version 1.18 has an infinite loop vulnerability in the ChmParser. A remote attacker could exploit this to cause a denial of service via crafted file. External References: https://lists.apache.org/thread.html/4d2cb5c819401bb075e2a1130e0d14f0404a136541a6f91da0225828@%3Cdev.tika.apache.org%3E References: https://bugzilla.redhat.com/show_bug.cgi?id=1572424 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-1339 http://seclists.org/oss-sec/2018/q2/74 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-1339.html https://access.redhat.com/security/cve/CVE-2018-1339 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1339 https://lists.apache.org/thread.html/4d2cb5c819401bb075e2a1130e0d14f0404a136541a6f91da0225828@%3Cdev.tika.apache.org%3E
Not affected, closing.