CVE-2020-1951

CVSS v3.1 5.5 (Medium)
55% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.06 % (24th)
0.06% Progress
Affected Products 6
Advisories 2

A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

Weaknesses
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2020-03-23 14:15:13
(4 years ago)
Updated Date
2022-10-07 01:59:36
(23 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Tika from 1.0 version and 1.23 and prior versions cpe:2.3:a:apache:tika >= 1.0 <= 1.23

Configuration #2

    CPE23 From Up To
  Oracle Business Process Management Suite 12.2.1.3.0 cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0
  Oracle Business Process Management Suite 12.2.1.4.0 cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0
  Oracle Communications Messaging Server 8.0.2 cpe:2.3:a:oracle:communications_messaging_server:8.0.2
  Oracle Communications Messaging Server 8.1 cpe:2.3:a:oracle:communications_messaging_server:8.1
  Oracle Flexcube Private Banking 12.0.0 cpe:2.3:a:oracle:flexcube_private_banking:12.0.0
  Oracle Flexcube Private Banking 12.1.0 cpe:2.3:a:oracle:flexcube_private_banking:12.1.0
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...