CVE-2019-20421: High severity exiv2 exiv2 vulnerability
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20421?
CVE-2019-20421 has a high severity rating as it can lead to a denial of service through high CPU consumption.
How do I fix CVE-2019-20421?
To fix CVE-2019-20421, update the Exiv2 package to a version that is not vulnerable, such as version 0.27.3-3+deb11u2 or later.
What types of attacks can exploit CVE-2019-20421?
CVE-2019-20421 can be exploited by remote attackers using crafted input files that cause an infinite loop.
Which software versions are affected by CVE-2019-20421?
CVE-2019-20421 affects Exiv2 versions prior to 0.27.3 and various specific versions of the package on Ubuntu and Debian systems.
Is there a known patch for CVE-2019-20421?
Yes, patches are available in newer releases of the Exiv2 software that address CVE-2019-20421.