CVE-2022-25169

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*

History

09 Nov 2022, 21:26

Type Values Removed Values Added
References (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - Third Party Advisory
References (CONFIRM) https://security.netapp.com/advisory/ntap-20220804-0004/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20220804-0004/ - Third Party Advisory
CPE cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
First Time Oracle primavera Unifier
Oracle

04 Aug 2022, 18:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20220804-0004/ -

25 Jul 2022, 18:22

Type Values Removed Values Added
References
  • (N/A) https://www.oracle.com/security-alerts/cpujul2022.html -

25 May 2022, 18:01

Type Values Removed Values Added
CPE cpe:2.3:a:apache:tika:2.4.0:*:*:*:*:*:*:*

25 May 2022, 02:54

Type Values Removed Values Added
First Time Apache tika
Apache
CPE cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tika:2.4.0:*:*:*:*:*:*:*
CWE CWE-770
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.5
References (CONFIRM) https://lists.apache.org/thread/t3tb51sf0k2pmbnzsrrrm23z9r1c10rk - (CONFIRM) https://lists.apache.org/thread/t3tb51sf0k2pmbnzsrrrm23z9r1c10rk - Mailing List, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/05/16/4 - (MLIST) http://www.openwall.com/lists/oss-security/2022/05/16/4 - Mailing List, Third Party Advisory

16 May 2022, 21:59

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/05/16/4 -

16 May 2022, 18:15

Type Values Removed Values Added
Summary The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

16 May 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-16 17:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-25169

Mitre link : CVE-2022-25169

CVE.ORG link : CVE-2022-25169


JSON object : View

Products Affected

oracle

  • primavera_unifier

apache

  • tika
CWE
CWE-770

Allocation of Resources Without Limits or Throttling