CVE-2019-20421 PUBLISHED

In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

EPSS 3.07% · 86.6th percentile

Risk Scores

EPSS Score
3.07%
86.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSexiv20, 0.25-1ubuntu1, 0.25-2.1
Ubuntu:18.04:LTSexiv20, 0.25-3.1ubuntu0.18.04.1, 0.25-3.1ubuntu0.18.04.3

Timeline

References

Open in Interactive Console →