CVE-2019-20421
27.01.2020, 05:15
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| exiv2 | exiv2 | 0.27.2 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.10 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| exiv2 |
| ||
| exiv2-devel |
| ||
| exiv2-doc |
| ||
| exiv2-libs |
| ||
| gegl |
| ||
| gnome-color-manager |
| ||
| libgexiv2 |
| ||
| libgexiv2-devel |
|
Common Weakness Enumeration
References