CVE-2020-1950
CVE-2020-1950
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 2.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
23 Mar 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
Affected products
Apache · Apache TikaWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://lists.apache.org/thread.html/r463b1a67817ae55fe022536edd6db34e8f9636971188430cbcf8a8dd%40%3Cdev.tika.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/03/msg00035.htmlhttps://usn.ubuntu.com/4564-1/https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html