Back to search
CVE-2016-6809
Published: Apr 6, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
94247
vdb-entry
x_refsource_BID
https://dist.apache.org/repos/dist/release/tika/CHANGES-1.14.txt
x_refsource_MISC
http://seclists.org/bugtraq/2016/Nov/40
x_refsource_CONFIRM
[lucene-dev] 20190325 Re: 6.6.6 Release
mailing-list
x_refsource_MLIST
[nutch-dev] 20191014 [SECURITY] Nutch 2.3.1 affected by downstream dependency CVE-2016-6809
mailing-list
x_refsource_MLIST
[nutch-user] 20191014 [SECURITY] Nutch 2.3.1 affected by downstream dependency CVE-2016-6809
mailing-list
x_refsource_MLIST
[lucene-issues] 20200815 [jira] [Commented] (SOLR-11486) CVE-2016-6809: Upgrade TIKA
mailing-list
x_refsource_MLIST
[lucene-issues] 20200816 [jira] [Issue Comment Deleted] (SOLR-11486) CVE-2016-6809: Upgrade TIKA
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now