Two security issues have been detected in tika and fixed. CVE-2020-1950: . Package : tika Version : 1.5-1+deb8u1 CVE ID : CVE-2020-1950 CVE-2020-1951 Debian Bug : 954302 954303 Two security issues have been detected in tika and fixed. CVE-2020-1950: carefully crafted or corrupt PSD file can cause excessive memory usage in Apache. CVE-2020-1951: Infinite Loop (DoS) vulnerability in Apache Tika's PSDParser. For Debian 8 "Jessie", these problems have been fixed in version 1.5-1+deb8u1. We recommend that you upgrade your tika packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS delivers critical patches for libxml2 targeting buffer overflows and service disruption vulnerabilities. Update your software today.. Tika Security Update, Debian LTS, DoS Vulnerability, Memory Issue. . Severity: Critical. LinuxSecurity.com Team
Update to newer release of Tika including security fixes for CVE-2016-4434 and CVE-2016-6809.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-639385f5ec 2018-04-27 23:05:32.367776 --------------------------------------------------------------------------------Name : tika Product : Fedora 28 Version : 1.17 Release : 1.fc28 URL : https://tika.apache.org/ Summary : A content analysis toolkit Description : The Apache Tika toolkit detects and extracts meta-data and structured text content from various documents using existing parser libraries. --------------------------------------------------------------------------------Update Information: Update to newer release of Tika including security fixes for CVE-2016-4434 and CVE-2016-6809. --------------------------------------------------------------------------------ChangeLog: * Thu Apr 19 2018 Mat Booth - 1.17-1 - Update to latest upstream release * Thu Apr 19 2018 Mat Booth - 1.12-6 - Drop uneeded dep on CXF --------------------------------------------------------------------------------References: [ 1 ] Bug #1394156 - CVE-2016-6809 tika: Native deserialization of Java objects in matlab files https://bugzilla.redhat.com/show_bug.cgi?id=1394156 [ 2 ] Bug #1340386 - CVE-2016-4434 tika: XML External Entity vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1340386 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-639385f5ec' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.