4.3
CVSSv2

CVE-2020-1951

Published: 23/03/2020 Updated: 07/10/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tika

oracle flexcube private banking 12.1.0

oracle flexcube private banking 12.0.0

debian debian linux 8.0

oracle business process management suite 12.2.1.3.0

canonical ubuntu linux 16.04

oracle business process management suite 12.2.1.4.0

oracle communications messaging server 8.1

oracle communications messaging server 8.0.2

Vendor Advisories

Debian Bug report logs - #954302 tika: CVE-2020-1951 Package: src:tika; Maintainer for src:tika is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 19 Mar 2020 21:03:01 UTC Severity: grave Tags: security, upstream Found in versio ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [CVE-2020-1951] Infinite Loop (DoS) vulnerability in Apache Tika's PSDParser <!--X-Subject-Header-End--> <!--X-Head-of-Message ...