2019-03-26 19:00:51 +00:00
{
2020-01-15 20:01:19 +00:00
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"data_version" : "4.0" ,
"CVE_data_meta" : {
"ID" : "CVE-2019-10088" ,
"ASSIGNER" : "security@apache.org" ,
"STATE" : "PUBLIC"
2019-08-02 19:00:51 +00:00
} ,
2020-01-15 20:01:19 +00:00
"affects" : {
"vendor" : {
"vendor_data" : [
2019-08-02 19:00:51 +00:00
{
2020-01-15 20:01:19 +00:00
"vendor_name" : "Apache" ,
"product" : {
"product_data" : [
2019-08-02 19:00:51 +00:00
{
2020-01-15 20:01:19 +00:00
"product_name" : "Apache Tika" ,
"version" : {
"version_data" : [
2019-08-02 19:00:51 +00:00
{
2020-01-15 20:01:19 +00:00
"version_value" : "1.7 to 1.21"
2019-08-02 19:00:51 +00:00
}
]
}
}
]
}
}
]
}
} ,
2020-01-15 20:01:19 +00:00
"problemtype" : {
"problemtype_data" : [
2019-08-02 19:00:51 +00:00
{
2020-01-15 20:01:19 +00:00
"description" : [
2019-08-02 19:00:51 +00:00
{
2020-01-15 20:01:19 +00:00
"lang" : "eng" ,
"value" : "DoS/OOM"
2019-08-02 19:00:51 +00:00
}
]
}
]
} ,
2020-01-15 20:01:19 +00:00
"references" : {
"reference_data" : [
2019-08-02 19:00:51 +00:00
{
2020-01-15 20:01:19 +00:00
"refsource" : "CONFIRM" ,
"name" : "https://lists.apache.org/thread.html/1c63555609b737c20d1bbfa4a3e73ec488e3408a84e2f5e47e1b7e08@%3Cdev.tika.apache.org%3E" ,
"url" : "https://lists.apache.org/thread.html/1c63555609b737c20d1bbfa4a3e73ec488e3408a84e2f5e47e1b7e08@%3Cdev.tika.apache.org%3E"
2019-08-09 16:00:52 +00:00
} ,
{
2020-01-15 20:01:19 +00:00
"refsource" : "MLIST" ,
"name" : "[tika-dev] 20190809 security fixes for CVE-2019-10088 and CVE-2019-1009{3,4}" ,
"url" : "https://lists.apache.org/thread.html/fb6c84fd387de997e5e366d50b0ca331a328c466432c80f8c5eed33d@%3Cdev.tika.apache.org%3E"
2019-08-12 19:00:50 +00:00
} ,
{
2020-01-15 20:01:19 +00:00
"refsource" : "MLIST" ,
"name" : "[tika-dev] 20190812 Re: security fixes for CVE-2019-10088 and CVE-2019-1009{3,4}" ,
"url" : "https://lists.apache.org/thread.html/da9ee189d1756f8508d0f2386d8e25aca5a6df541739829232be8a94@%3Cdev.tika.apache.org%3E"
2019-08-13 08:00:51 +00:00
} ,
{
2020-01-15 20:01:19 +00:00
"refsource" : "MLIST" ,
"name" : "[tika-dev] 20190813 Re: security fixes for CVE-2019-10088 and CVE-2019-1009{3,4}" ,
"url" : "https://lists.apache.org/thread.html/39723d8227b248781898c200aa24b154683673287b150a204b83787d@%3Cdev.tika.apache.org%3E"
2019-08-28 13:00:51 +00:00
} ,
{
2020-01-15 20:01:19 +00:00
"refsource" : "CONFIRM" ,
"name" : "https://security.netapp.com/advisory/ntap-20190828-0004/" ,
"url" : "https://security.netapp.com/advisory/ntap-20190828-0004/"
2020-01-14 15:46:23 -08:00
} ,
{
2020-01-15 20:01:19 +00:00
"url" : "https://www.oracle.com/security-alerts/cpujan2020.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpujan2020.html"
2019-08-02 19:00:51 +00:00
}
]
2019-03-26 19:00:51 +00:00
} ,
2020-01-15 20:01:19 +00:00
"description" : {
"description_data" : [
2019-03-26 19:00:51 +00:00
{
2020-01-15 20:01:19 +00:00
"lang" : "eng" ,
"value" : "A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later."
2019-03-26 19:00:51 +00:00
}
]
}
}