CVE-2020-1951
published 2020-03-23CVE-2020-1951: A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
2.83%
85.1th percentile
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| apache | tika | >= 0 < 1.22-2 | 1.22-2 |
| apache | tika | >= 0 < 1.5-4ubuntu0.1 | 1.5-4ubuntu0.1 |
| apache | tika | >= 0 < 1.22-1ubuntu0.1~esm1 | 1.22-1ubuntu0.1~esm1 |
| apache | tika | >= 0 < 1.22-2ubuntu0.22.04.1~esm1 | 1.22-2ubuntu0.22.04.1~esm1 |
| apache | tika | 1.0 – 1.23 | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | tika | < tika 1.22-2 (bullseye) | tika 1.22-2 (bullseye) |
| oracle | business_process_management_suite | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_apache5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tika vulnerabilities
osv·2025-05-23·CVSS 5.5
CVE-2020-1950 [MEDIUM] tika vulnerabilities
tika vulnerabilities
It was discovered that Apache Tika can have an excessive memory usage by
using a crafted or corrupt PSD file. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2020-1950, CVE-2020-1951)
It was discovered that Apache Tika incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause a denial
of service. (CVE-2022-30126, CVE-2022-30973, CVE-2022-33879)
GHSA
Infinite Loop in Apache Tika
ghsa·2021-05-07
CVE-2020-1951 [MEDIUM] CWE-835 Infinite Loop in Apache Tika
Infinite Loop in Apache Tika
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
OSV
Infinite Loop in Apache Tika
osv·2021-05-07
CVE-2020-1951 [MEDIUM] Infinite Loop in Apache Tika
Infinite Loop in Apache Tika
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
OSV
tika vulnerabilities
osv·2020-10-05·CVSS 5.5
CVE-2020-1950 [MEDIUM] tika vulnerabilities
tika vulnerabilities
It was discovered that Apache Tika can have an excessive memory usage by
using a crafted or corrupt PSD file. An attacker could use it to cause a
denial of service (crash). (CVE-2020-1950, CVE-2020-1951)
OSV
CVE-2020-1951: A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1
osv·2020-03-23·CVSS 5.5
CVE-2020-1951 [MEDIUM] CVE-2020-1951: A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
Ubuntu
Apache Tika vulnerabilities
vendor_ubuntu·2025-05-23·CVSS 5.5
CVE-2022-30126 [MEDIUM] Apache Tika vulnerabilities
Title: Apache Tika vulnerabilities
Summary: Several security issues were fixed in Apache Tika.
It was discovered that Apache Tika can have an excessive memory usage by
using a crafted or corrupt PSD file. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2020-1950, CVE-2020-1951)
It was discovered that Apache Tika incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause a denial
of service. (CVE-2022-30126, CVE-2022-30973, CVE-2022-33879)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Core (Apache Tika) — CVE-2020-1951
vendor_oracle·2020-10-15·CVSS 5.5
CVE-2020-1951 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Core (Apache Tika) — CVE-2020-1951
Oracle Oracle Financial Services Applications Risk Matrix: Core (Apache Tika) vulnerability
CVE: CVE-2020-1951
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2020 (OCT 2020)
Ubuntu
Apache Tika vulnerabilities
vendor_ubuntu·2020-10-05·CVSS 5.5
CVE-2020-1951 [MEDIUM] Apache Tika vulnerabilities
Title: Apache Tika vulnerabilities
Summary: Apache Tika could be made to crash if it opened a specially crafted
file.
It was discovered that Apache Tika can have an excessive memory usage by
using a crafted or corrupt PSD file. An attacker could use it to cause a
denial of service (crash). (CVE-2020-1950, CVE-2020-1951)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Apache Tika) — CVE-2020-1951
vendor_oracle·2020-07-15·CVSS 5.5
CVE-2020-1951 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Security (Apache Tika) — CVE-2020-1951
Oracle Oracle Communications Applications Risk Matrix: Security (Apache Tika) vulnerability
CVE: CVE-2020-1951
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2020 (JUL 2020)
Debian
CVE-2020-1951: tika - A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tik...
vendor_debian·2020·CVSS 5.5
CVE-2020-1951 [MEDIUM] CVE-2020-1951: tika - A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tik...
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
Scope: local
bullseye: resolved (fixed in 1.22-2)
sid: resolved (fixed in 1.22-2)
Apache
Apache tika: CVE-2020-1951
vendor_apache·CVSS 5.5
CVE-2020-1951 [MEDIUM] Apache tika: CVE-2020-1951
Apache tika: CVE-2020-1951
Infinite Loop (DoS) vulnerability in Apache Tika's PSDParser Tim Allison 1.0-1.23
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1951 tika: crafted or corrupt PSD file leads to DoS [fedora-all]
bugzilla·2020-05-05·CVSS 5.5
CVE-2020-1951 [MEDIUM] CVE-2020-1951 tika: crafted or corrupt PSD file leads to DoS [fedora-all]
CVE-2020-1951 tika: crafted or corrupt PSD file leads to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2020-1951 tika: crafted or corrupt PSD file leads to DoS
bugzilla·2020-05-05·CVSS 5.5
CVE-2020-1951 [MEDIUM] CVE-2020-1951 tika: crafted or corrupt PSD file leads to DoS
CVE-2020-1951 tika: crafted or corrupt PSD file leads to DoS
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
Reference:
https://lists.apache.org/thread.html/rd8c1b42bd0e31870d804890b3f00b13d837c528f7ebaf77031323172%40%3Cdev.tika.apache.org%3E
Discussion:
Created tika tracking bugs for this issue:
Affects: fedora-all [bug 1831708]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
https://lists.apache.org/thread.html/rd8c1b42bd0e31870d804890b3f00b13d837c528f7ebaf77031323172%40%3Cdev.tika.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/03/msg00035.htmlhttps://usn.ubuntu.com/4564-1/https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://lists.apache.org/thread.html/rd8c1b42bd0e31870d804890b3f00b13d837c528f7ebaf77031323172%40%3Cdev.tika.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/03/msg00035.htmlhttps://usn.ubuntu.com/4564-1/https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-03-23
Published