CVE-2020-1950
published 2020-03-23CVE-2020-1950: A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_tika | — | — |
| apache | tika | — | — |
| apache | tika | >= 0 < 1.22-2 | 1.22-2 |
| apache | tika | >= 0 < 1.5-4ubuntu0.1 | 1.5-4ubuntu0.1 |
| apache | tika | >= 0 < 1.22-1ubuntu0.1~esm1 | 1.22-1ubuntu0.1~esm1 |
| apache | tika | >= 0 < 1.22-2ubuntu0.22.04.1~esm1 | 1.22-2ubuntu0.22.04.1~esm1 |
| apache | tika | 1.0 – 1.23 | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | tika | < tika 1.22-2 (bullseye) | tika 1.22-2 (bullseye) |
| oracle | business_process_management_suite | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM