[ANNOUNCE] Apache Tika 1.16 released

2017-07-12 Thread Tim Allison
://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 1.15 released

2017-05-30 Thread Tim Allison
not be available on all mirrors. When downloading from a mirror site, please remember to verify the downloads using signatures found on the Apache site: https://people.apache.org/keys/group/tika.asc For more information on Apache Tika, visit the project home page: http://tika.apache.org/ -- Tim

[ANNOUNCE] Apache Tika 1.17 released

2017-12-13 Thread Tim Allison
://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

CVE-2017-12626 – Denial of Service Vulnerabilities in Apache POI < 3.17

2018-01-26 Thread Tim Allison
ich accept content from external or untrusted sources are advised to upgrade to Apache POI 3.17 or newer. -Tim Allison on behalf of the Apache POI PMC   [0] https://bz.apache.org/bugzilla/show_bug.cgi?id=61338 [1] https://bz.apache.org/bugzilla/show_bug.cgi?id=61294 [2] https://bz.apache.org/bugzi

[CVE-2018-1335] Command Injection Vulnerability in Apache Tika’s tika-server module

2018-04-25 Thread Tim Allison
Credit: Tim Allison, a member of the Apache Tika team, discovered this.

Fwd: [ANNOUNCE] Apache Tika 1.18 released

2018-04-25 Thread Tim Allison
. When downloading from a mirror site, please remember to verify the downloads using signatures found on the Apache site: http://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: http://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika

[CVE-2018-11796] Apache Tika Denial of Service via XML Entity Expansion Vulnerability

2018-10-09 Thread Tim Allison
CVE-2018-11796: Apache Tika Denial of Service via XML Entity Expansion Vulnerability Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Tika 0.1 to 1.19 Description: In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing.

[ANNOUNCE] Apache Tika 1.19.1 released

2018-10-09 Thread Tim Allison
on all mirrors. When downloading from a mirror site, please remember to verify the downloads using signatures found on the Apache site: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf

[CVE-2018-11761] Apache Tika DoS XML Entity Expansion Vulnerability

2018-09-19 Thread Tim Allison
CVE-2018-11761: Apache Tika Denial of Service via XML Entity Expansion Vulnerability Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Tika 0.1 to 1.18 Description: Apache Tika's XML parsers were not configured to limit entity expansion. They were therefore

[CVE-2018-11762] Zip Slip Vulnerability in Apache Tika's tika-app

2018-09-19 Thread Tim Allison
file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file. Mitigation: Apache Tika users should upgrade to 1.19 or later Credit: This issue was discovered by Tim Allison on the Apache Tika team.

[CVE-2018-8017] Apache Tika Denial of Service Vulnerability -- Potential Infinite Loop in IptcAnpaParser

2018-09-19 Thread Tim Allison
CVE-2018-8017: Apache Tika Denial of Service Vulnerability -- Potential Infinite Loop in IptcAnpaParser Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Tika 1.2 to 1.18 Description: A carefully crafted file can trigger an infinite loop in Apache Tika's

[ANNOUNCE] Apache Tika 1.19 released

2018-09-19 Thread Tim Allison
a mirror site, please remember to verify the downloads using signatures found on the Apache site: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: http://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[CVE-2018-17197] Apache Tika Denial of Service -- Infinite Loop in Tika's SQLite3Parser

2018-12-22 Thread Tim Allison
SQLite3Parser in versions 1.8-1.19.1 of Apache Tika. Mitigation: Apache Tika users should upgrade to 1.20 or later. Credit: This issue was discovered by Tim Allison on the Apache Tika Team.

[ANNOUNCE] Apache Tika 1.20 released

2018-12-22 Thread Tim Allison
a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 1.21 released

2019-05-20 Thread Tim Allison
a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[CVE-2019-10088] OOM from a crafted Zip File in Apache Tika's RecursiveParserWrapper

2019-08-02 Thread Tim Allison
Title: [CVE-2019-10088] OOM from a crafted Zip File in Apache Tika's RecursiveParserWrapper Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Tika 1.7 to 1.21 Description: A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's

[CVE-2019-10093] Denial of Service in Apache Tika's 2003ml and 2006ml Parsers

2019-08-02 Thread Tim Allison
and lead to very long hangs. Mitigation: Apache Tika users should upgrade to 1.22 or later. Credit: This issue was discovered by Tim Allison on the Apache Tika team.

[ANNOUNCE] Apache Tika 1.22 released

2019-08-02 Thread Tim Allison
Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[CVE-2019-10094] StackOverflow from Crafted Package/Compressed Files in Apache Tika's RecursiveParserWrapper

2019-08-02 Thread Tim Allison
/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21 of Apache Tika. Mitigation: Apache Tika users should upgrade to 1.22 or later. Credit: This issue was discovered by Tim Allison on the Apache Tika team. Many

[ANNOUNCE] Apache Tika 1.23 released

2019-12-06 Thread Tim Allison
a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[CVE-2020-9489] Denial of Service (DOS) Vulnerabilities in Some of Apache Tika's Parsers

2020-04-24 Thread Tim Allison
: These vulnerabilities were discovered by Tim Allison on the Apache Tika team.

[ANNOUNCE] Apache Tika 1.24.1 released

2020-04-22 Thread Tim Allison
from a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 1.24 released

2020-03-18 Thread Tim Allison
a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[CVE-2020-1951] Infinite Loop (DoS) vulnerability in Apache Tika's PSDParser

2020-03-18 Thread Tim Allison
in versions 1.0-1.23. Mitigation: Apache Tika users should upgrade to 1.24 or later. Credit: This issue was discovered by Tim Allison on the Apache Tika team.

[CVE-2020-1950] Excessive memory usage (DoS) vulnerability in Apache Tika's PSDParser

2020-03-18 Thread Tim Allison
Title: [CVE-2020-1950] Excessive memory usage (DoS) vulnerability in Apache Tika's PSDParser Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Tika 1.0 to 1.23 Description: A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache

[ANNOUNCE] Apache Tika 1.25 released

2020-12-02 Thread Tim Allison
a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.0.0-ALPHA released

2021-01-19 Thread Tim Allison
downloading from a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.0.0-BETA released

2021-06-01 Thread Tim Allison
mirrors. When downloading from a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 1.27 released

2021-07-07 Thread Tim Allison
from a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

CVE-2021-28657: Infinite loop in Apache Tika's MP3 parser

2021-03-30 Thread Tim Allison
Description: A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later. Mitigation: Users should upgrade to 1.26 or later. Credit: Apache Tika would like to thank Khaled Nassar for

[ANNOUNCE] Apache Tika 1.26 released

2021-03-29 Thread Tim Allison
a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.1.0 released

2021-08-30 Thread Tim Allison
downloading from a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 1.28 released

2021-12-23 Thread Tim Allison
/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.2.1 released

2021-12-23 Thread Tim Allison
using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.2.0 released

2021-12-16 Thread Tim Allison
: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.0.0 released

2021-07-21 Thread Tim Allison
downloading from a mirror site, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 1.28.1 released

2022-02-11 Thread Tim Allison
://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.3.0 released

2022-02-07 Thread Tim Allison
://repo1.maven.org/maven2/org/apache/tika/ When downloading, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika

[ANNOUNCE] Apache Tika 1.x End-Of-Life (EOL) announcement

2022-02-11 Thread Tim Allison
The Apache Tika Project Team would like to inform you that the Apache Tika 1.x branch is now in security-only maintenance until September 30, 2022. After that date, we will not make updates or releases from our 1.x branch. We will continue to make security fixes and security-related dependency

[ANNOUNCE] Apache Tika 2.9.1 released

2023-10-22 Thread Tim Allison
, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

CVE-2022-25169: Apache Tika BPGParser Memory Usage DoS

2022-05-17 Thread Tim Allison
Description: The BPG parser in versions of Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

CVE-2022-30973: Apache Tika: Missing fix for CVE-2022-30126 in 1.28.2

2022-06-01 Thread Tim Allison
Description: We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted

[ANNOUNCE] Apache Tika 1.28.3 released

2022-05-27 Thread Tim Allison
://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

CVE-2022-30126: Apache Tika Regular Expression Denial of Service in Standards Extractor

2022-05-16 Thread Tim Allison
Severity: low Description: A regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which

[ANNOUNCE] Apache Tika 1.28.4 released

2022-06-22 Thread Tim Allison
://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.4.1 released

2022-06-22 Thread Tim Allison
For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

CVE-2022-33879: Apache Tika: Incomplete fix and new regex DoS in StandardsExtractingContentHandler

2022-06-28 Thread Tim Allison
Severity: low Description: The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1

[ANNOUNCE] Apache Tika 1.28.2 released

2022-05-03 Thread Tim Allison
Repository: https://repo1.maven.org/maven2/org/apache/tika/ When downloading, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf

[ANNOUNCE] Apache Tika 2.4.0 released

2022-05-03 Thread Tim Allison
to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 1.28.5 released

2022-09-14 Thread Tim Allison
/ When downloading, please remember to verify the downloads using signatures found: https://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.5.0 released

2022-10-03 Thread Tim Allison
, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.6.0 released

2022-11-07 Thread Tim Allison
://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

ANNOUNCE] Apache Tika 2.7.0 released

2023-02-06 Thread Tim Allison
://www.apache.org/dist/tika/KEYS For more information on Apache Tika, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.8.0 released

2023-05-15 Thread Tim Allison
/ -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 3.0.0-BETA released

2023-12-13 Thread Tim Allison
ted CVEs: CVE-2023-6481/CVE-2023-6378. NOTE: This release requires Java 11. We plan to support the 2.x branch (which requires Java 8) for six months after the release of 3.0.0. -- Tim Allison, on behalf of the Apache Tika community

[ANNOUNCE] Apache Tika 2.9.2 released

2024-04-02 Thread Tim Allison
, visit the project home page: https://tika.apache.org/ -- Tim Allison, on behalf of the Apache Tika community