CVE-2018-17202

Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incubating) was renamed to Apache Commons Imaging.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:commons_imaging:0.97:*:*:*:*:*:*:*

History

07 Nov 2023, 02:54

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/69204376d12205b0d2d90e6fcbeebb99b894e6db88c8ff565c4e1efa@%3Cdev.commons.apache.org%3E', 'name': '[commons-dev] 20190503 [CVE-2018-17202]: Apache Commons Imaging information disclosure vulnerability', 'tags': ['Mailing List', 'Vendor Advisory'], 'refsource': 'MLIST'}
  • () https://lists.apache.org/thread.html/69204376d12205b0d2d90e6fcbeebb99b894e6db88c8ff565c4e1efa%40%3Cdev.commons.apache.org%3E -

Information

Published : 2019-05-06 18:29

Updated : 2023-12-10 12:59


NVD link : CVE-2018-17202

Mitre link : CVE-2018-17202

CVE.ORG link : CVE-2018-17202


JSON object : View

Products Affected

apache

  • commons_imaging
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')