Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:3311-1 Moderate: Tika-Engine DoS and Regex Vulnerabilities

suse
Calendar Grey September 19, 2022
Dist Suse Esm H88
A new patch for tika-core has been released, addressing three moderate severity security issues on SUSE Linux Enterprise, now successfully mitigated
An update that fixes three vulnerabilities is now available

Summary

This update for tika-core fixes the following issues: - CVE-2022-33879: Incomplete fix and new regex DoS in StandardsExtractingContentHandler. (bsc#1201217) - CVE-2022-30973, CVE-2022-30126: Regular Expression Denial of Service in Standards Extractor. (bsc#1199604, bsc#1200283) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for SUSE Manager Server 4.2: zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.2-2022-3310=1 Package List: - SUSE Linux Enterprise Module for SUSE Manager Server 4.2 (noarch): tika-core-1.26-150300.4.3.1

References

#1199604 #1200283 #1201217

Cross- CVE-2022-30126 CVE-2022-30973 CVE-2022-33879

CVSS scores:

CVE-2022-30126 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2022-30126 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-30973 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2022-30973 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-33879 (NVD) : 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CVE-2022-33879 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Module for SUSE Manager Server 4.2

SUSE Manager Server 4.2

https://www.suse.com/security/cve/CVE-2022-30126.html

https://www.suse.com/security/cve/CVE-2022-30973.html

Announcement ID: SUSE-SU-2022:3310-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here