oss-sec mailing list archives
CVE-2026-33582: Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error
From: Enxin Xie <linkinstar () apache org>
Date: Tue, 09 Jun 2026 05:15:39 +0000
Severity: important Affected versions: - Apache Answer through 2.0.0 Description: Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Credit: Andy Gill, ZephrSec Ltd (reporter) References: https://answer.apache.org https://www.cve.org/CVERecord?id=CVE-2026-33582
Current thread:
- CVE-2026-33582: Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error Enxin Xie (Jun 09)
