CVE Vulnerabilities

CVE-2020-9489

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Apr 27, 2020 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A carefully crafted or corrupt file may trigger a System.exit in Tikas OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tikas ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser were partially fixed by upgrading the com.googlecode:isoparser:1.1.22 dependency to org.tallison:isoparser:1.9.41.2. For unrelated security reasons, we upgraded org.apache.cxf to 3.3.6 as part of the 1.24.1 release.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Tika Apache 1.24 (including) 1.24 (including)
Red Hat Fuse 7.8.0 RedHat camel-tika *
Tika Ubuntu bionic *
Tika Ubuntu eoan *
Tika Ubuntu groovy *
Tika Ubuntu hirsute *
Tika Ubuntu impish *
Tika Ubuntu kinetic *
Tika Ubuntu lunar *
Tika Ubuntu mantic *
Tika Ubuntu trusty *
Tika Ubuntu xenial *

References