UBUNTU-CVE-2022-30973
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-30973
UBUNTU-CVE-2022-30973
Summary:
Details: We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3.
References: https://ubuntu.com/security/CVE-2022-30973, https://lists.apache.org/thread/gqvb5t4p7tmdpl0y5bdbf72pgxj04h7p, https://www.cve.org/CVERecord?id=CVE-2022-30973, https://ubuntu.com/security/notices/USN-7529-1
Affected packages
Package
Name: tika
Purl: pkg:deb/ubuntu/tika?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
