Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.113167
Kategorie:Web application abuses
Titel:Apache Tika Server 1.17 Multiple Vulnerabilities
Zusammenfassung:Apache Tika Server is prone to multiple vulnerabilities,; including Command Execution and Denial of Service
Beschreibung:Summary:
Apache Tika Server is prone to multiple vulnerabilities,
including Command Execution and Denial of Service

Vulnerability Insight:
The following vulnerabilities exist:

In Apache Tika, clients could send carefully crafted headers to tika-server that could be used to inject commands
into the command line of the server running tika-server.
This vulnerability only affects those running tika-server on a server that is open to untrusted clients.

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser.

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser.

Vulnerability Impact:
Successful exploitation could allow an attacker to eventually gain full control
over the target system.

Affected Software/OS:
Apache Tika Server through version 1.17.

Solution:
Update to version 1.18.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2018-1335
BugTraq ID: 104001
http://www.securityfocus.com/bid/104001
https://www.exploit-db.com/exploits/46540/
http://packetstormsecurity.com/files/153864/Apache-Tika-1.17-Header-Command-Injection.html
https://lists.apache.org/thread.html/b3ed4432380af767effd4c6f27665cc7b2686acccbefeb9f55851dca@%3Cdev.tika.apache.org%3E
RedHat Security Advisories: RHSA-2019:3140
https://access.redhat.com/errata/RHSA-2019:3140
Common Vulnerability Exposure (CVE) ID: CVE-2018-1338
https://lists.apache.org/thread.html/4d20c5748fb9f836653bc78a1bad991ba8485d82a1e821f70b641932@%3Cdev.tika.apache.org%3E
RedHat Security Advisories: RHSA-2018:2669
https://access.redhat.com/errata/RHSA-2018:2669
Common Vulnerability Exposure (CVE) ID: CVE-2018-1339
https://lists.apache.org/thread.html/4d2cb5c819401bb075e2a1130e0d14f0404a136541a6f91da0225828@%3Cdev.tika.apache.org%3E
CopyrightCopyright (C) 2018 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.