[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-11796 -- libtika-java

ID: oval:org.secpod.oval:def:1900684Date: (C)2019-03-29   (M)2023-12-20
Class: VULNERABILITYFamily: unix




In Apache Tika 1.19 , we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.

Platform:
Ubuntu 16.04
Ubuntu 18.10
Ubuntu 18.04
Product:
libtika-java
Reference:
CVE-2018-11796
CVE    1
CVE-2018-11796
CPE    4
cpe:/a:apache:libtika-java
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/o:ubuntu:ubuntu_linux:18.04
cpe:/o:ubuntu:ubuntu_linux:18.10
...

© SecPod Technologies