CVE-2022-25169

Description

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.313

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-30126,CVE-2022-25169 are fixed in Apache-tika 2.4.0Windows
Vulnerabilities CVE-2022-30126,CVE-2022-25169 are fixed in Apache-tika 1.28.2Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.1Windows
Vulnerabilities CVE-2022-30126,CVE-2022-25169 are fixed in Apache-tika for Linux 2.4.0Linux
Vulnerabilities CVE-2022-30126,CVE-2022-25169 are fixed in Apache-tika for Linux 1.28.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234