Uploaded image for project: 'Tika'
  1. Tika
  2. TIKA-3729

CVE-2022-24614 metadata-extractor: Out-of-memory when reading a specially crafted JPEG file

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 1.28.1, 2.3.0
    • 1.28.2, 2.4.0
    • metadata
    • None

    Description

      CVE-2022-24614 metadata-extractor: Out-of-memory when reading a specially crafted JPEG file

      When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.

       

      https://github.com/drewnoakes/metadata-extractor/issues/561

      Attachments

        Activity

          People

            tallison Tim Allison
            ldemasi Luigi De Masi
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: