CVE-2022-25169

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*

History

09 Nov 2022, 21:26

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
References (CONFIRM) https://security.netapp.com/advisory/ntap-20220804-0004/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20220804-0004/ - Third Party Advisory
References (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - Third Party Advisory

04 Aug 2022, 18:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20220804-0004/ -

25 Jul 2022, 18:22

Type Values Removed Values Added
References
  • (N/A) https://www.oracle.com/security-alerts/cpujul2022.html -

25 May 2022, 18:01

Type Values Removed Values Added
CPE cpe:2.3:a:apache:tika:2.4.0:*:*:*:*:*:*:*

25 May 2022, 02:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.5
CWE CWE-770
CPE cpe:2.3:a:apache:tika:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*
References (CONFIRM) https://lists.apache.org/thread/t3tb51sf0k2pmbnzsrrrm23z9r1c10rk - (CONFIRM) https://lists.apache.org/thread/t3tb51sf0k2pmbnzsrrrm23z9r1c10rk - Mailing List, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/05/16/4 - (MLIST) http://www.openwall.com/lists/oss-security/2022/05/16/4 - Mailing List, Third Party Advisory

16 May 2022, 21:59

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/05/16/4 -

16 May 2022, 18:15

Type Values Removed Values Added
Summary The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

16 May 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-16 17:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-25169

Mitre link : CVE-2022-25169

CVE.ORG link : CVE-2022-25169


JSON object : View

Products Affected

oracle

  • primavera_unifier

apache

  • tika
CWE
CWE-770

Allocation of Resources Without Limits or Throttling