Infinite loop in Exiv2 - CVE-2019-20421

 

Infinite loop in Exiv2 - CVE-2019-20421

Published: June 8, 2020 / Updated: June 30, 2020


Vulnerability identifier: #VU28798
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20421
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the Jp2Image::readMetadata() in jp2image.cpp. A remote attacker can create a specially crafted image file, pass it to the affected application and consume all available system resources or cause denial of service conditions.


Affected software

Exiv2
exiv2 (Debian package)
exiv2 (Alpine package)

How to mitigate CVE-2019-20421

Install update from vendor's website.

Exiv2 - update to 0.27.3
exiv2 (Debian package) - update to 0.25-4+deb10u2
exiv2 (Alpine package) - update to 0.27.2-r3

External References

Related Security Bulletins