CVE-2020-1951: Medium severity Apache Tika vulnerability
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tikato a version that resolves this vulnerability.Fixed in 1.22-2+deb11u1Fixed in 1.22-2
Event History
Frequently Asked Questions
What is CVE-2020-1951?
CVE-2020-1951 is a vulnerability in Apache Tika's PSDParser that can be triggered by a carefully crafted or corrupt PSD file, leading to an infinite loop.
How severe is CVE-2020-1951?
CVE-2020-1951 has a severity rating of 5.5 (medium) on the CVSS scale.
Which software versions are affected by CVE-2020-1951?
Apache Tika versions 1.0-1.23 are affected by CVE-2020-1951. Additionally, Oracle Business Process Management Suite versions 12.2.1.3.0 and 12.2.1.4.0, Oracle Communications Messaging Server versions 8.0.2 and 8.1, and Oracle FLEXCUBE Private Banking versions 12.0.0 and 12.1.0 are also affected.
How can CVE-2020-1951 be exploited?
CVE-2020-1951 can be exploited by using a carefully crafted or corrupt PSD file as input to Apache Tika's PSDParser.
Are there any remedies available for CVE-2020-1951?
For Apache Tika, upgrading to version 1.22-2 or later is recommended. For other affected software, please refer to the respective vendors' advisories for available patches or updates.