Loop with Unreachable Exit Condition ('Infinite Loop') Affecting tika package, versions *
Threat Intelligence
EPSS
0.08% (35th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN10-TIKA-1089789
- published 31 Mar 2021
- disclosed 31 Mar 2021
Introduced: 31 Mar 2021
CVE-2021-28657 Open this link in a new tabHow to fix?
There is no fixed version for Debian:10 tika.
NVD Description
Note: Versions mentioned in the description apply only to the upstream tika package and not the tika package as distributed by Debian.
See How to fix? for Debian:10 relevant fixed versions and status.
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
References
- https://security-tracker.debian.org/tracker/CVE-2021-28657
- https://security.netapp.com/advisory/ntap-20210507-0004/
- https://lists.apache.org/thread.html/r915add4aa52c60d1b5cf085039cfa73a98d7fae9673374dfd7744b5a%40%3Cdev.tika.apache.org%3E
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b@%3Cnotifications.james.apache.org%3E
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b%40%3Cnotifications.james.apache.org%3E
CVSS Scores
version 3.1