Infinite loop in Apache Tika's MP3 parser
CVE-2021-28657

5.5MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
31 March 2021

Summary

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.

Affected Version(s)

Apache Tika Apache Tika < 1.26

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Tika would like to thank Khaled Nassar for reporting this issue.
.