SB2020031536 - Infinite loop in exiv2 (Alpine package)
Published: March 15, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Infinite loop (CVE-ID: CVE-2019-20421)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the Jp2Image::readMetadata() in jp2image.cpp. A remote attacker can create a specially crafted image file, pass it to the affected application and consume all available system resources or cause denial of service conditions.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=4b80232f5a78abca62be25e8a44812437d3f11ef
- https://git.alpinelinux.org/aports/commit/?id=5f508d129e5e87f82b2c8e85793d0c5302c5ef23
- https://git.alpinelinux.org/aports/commit/?id=3e8ab963c14f906a03b0638a994acc710657355b
- https://git.alpinelinux.org/aports/commit/?id=f7de796e6aaa9b44eed3b77e1c0e66fff453d454