[ 
https://issues.apache.org/jira/browse/TIKA-4199?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17818846#comment-17818846
 ] 

Tim Allison commented on TIKA-4199:
-----------------------------------

Thank you [~tilman] for working on this! I'm sorry I opened a duplicate ticket.

To confirm, the current workaround is to write each embedded file to disc 
instead of handling in memory --> {{tis.getPath()}}

If I have any time, I'll see if I can create a small reproducer for the 
commons-compress team that uses mark/reset on a wrapped ArchiveInputStream. To 
be clear, without looking further, I'm not declaring this a problem with 
commons-compress! :D


> commons-compress 1.26.0 breaks Apache Tika 2.9.1
> ------------------------------------------------
>
>                 Key: TIKA-4199
>                 URL: https://issues.apache.org/jira/browse/TIKA-4199
>             Project: Tika
>          Issue Type: Bug
>          Components: parser
>    Affects Versions: 2.9.1
>            Reporter: Alexander Veit
>            Priority: Major
>
> An update to commons-compress 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 
> breaks Tika.
>  
> For more information see https://issues.apache.org/jira/browse/COMPRESS-661.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to