Vulnerabilities > CVE-2020-1951 - Infinite Loop vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | Apache
| 25 |
Application | 6 | |
OS | 1 | |
OS | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DLA-2161.NASL |
description | Two security issues have been detected in tika and fixed. CVE-2020-1950: carefully crafted or corrupt PSD file can cause excessive memory usage in Apache. CVE-2020-1951: Infinite Loop (DoS) vulnerability in Apache Tika |
last seen | 2020-04-03 |
modified | 2020-03-30 |
plugin id | 134982 |
published | 2020-03-30 |
reporter | This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/134982 |
title | Debian DLA-2161-1 : tika security update |
code |
|
References
- https://lists.apache.org/thread.html/rd8c1b42bd0e31870d804890b3f00b13d837c528f7ebaf77031323172%40%3Cdev.tika.apache.org%3E
- https://lists.apache.org/thread.html/rd8c1b42bd0e31870d804890b3f00b13d837c528f7ebaf77031323172%40%3Cdev.tika.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2020/03/msg00035.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00035.html
- https://usn.ubuntu.com/4564-1/
- https://usn.ubuntu.com/4564-1/
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html