Infinite loop in Exiv2 - CVE-2019-20421
Published: June 8, 2020 / Updated: June 30, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the Jp2Image::readMetadata() in jp2image.cpp. A remote attacker can create a specially crafted image file, pass it to the affected application and consume all available system resources or cause denial of service conditions.
Affected software
exiv2 (Debian package)
exiv2 (Alpine package)
How to mitigate CVE-2019-20421
exiv2 (Debian package) - update to 0.25-4+deb10u2
exiv2 (Alpine package) - update to 0.27.2-r3