CVE-2018-8015

HIGH

Apache ORC 1.0.0-1.4.3 - Uncontrolled Recursion via Malformed ORC File

Title source: llm
STIX 2.1

Description

In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug is most likely denial-of-service against software that uses the ORC file parser. With the C++ parser, the stack overflow might possibly corrupt the stack.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://orc.apache.org/security/CVE-2018-8015/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104215

Scores

CVSS v3 7.5
EPSS 0.0415
EPSS Percentile 88.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-674
Status published
Products (2)
apache/orc 1.0.0 - 1.4.3
org.apache.orc/orc 1.0.0 - 1.4.4Maven
Published May 18, 2018
Tracked Since Feb 18, 2026