CVE-2022-25169

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*

History

09 Nov 2022, 21:26

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20220804-0004/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20220804-0004/ - Third Party Advisory
References (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - Third Party Advisory
CPE cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*

04 Aug 2022, 18:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20220804-0004/ -

25 Jul 2022, 18:22

Type Values Removed Values Added
References
  • (N/A) https://www.oracle.com/security-alerts/cpujul2022.html -

25 May 2022, 18:01

Type Values Removed Values Added
CPE cpe:2.3:a:apache:tika:2.4.0:*:*:*:*:*:*:*

25 May 2022, 02:54

Type Values Removed Values Added
CWE CWE-770
References (CONFIRM) https://lists.apache.org/thread/t3tb51sf0k2pmbnzsrrrm23z9r1c10rk - (CONFIRM) https://lists.apache.org/thread/t3tb51sf0k2pmbnzsrrrm23z9r1c10rk - Mailing List, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/05/16/4 - (MLIST) http://www.openwall.com/lists/oss-security/2022/05/16/4 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:tika:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.5

16 May 2022, 21:59

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/05/16/4 -

16 May 2022, 18:15

Type Values Removed Values Added
Summary The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

16 May 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-16 17:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-25169

Mitre link : CVE-2022-25169

CVE.ORG link : CVE-2022-25169


JSON object : View

Products Affected

apache

  • tika

oracle

  • primavera_unifier
CWE
CWE-770

Allocation of Resources Without Limits or Throttling