Description
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
References (5)
Core 5
Core References
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/03/msg00035.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Mailing List, Vendor Advisory x_refsource_misc
https://lists.apache.org/thread.html/rd8c1b42bd0e31870d804890b3f00b13d837c528f7ebaf77031323172%40%3Cdev.tika.apache.org%3E
Third Party Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/4564-1/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html
Scores
CVSS v3
5.5
EPSS
0.0021
EPSS Percentile
43.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-835
Status
published
Products (10)
apache/tika
1.0 - 1.23
canonical/ubuntu_linux
16.04
debian/debian_linux
8.0
oracle/business_process_management_suite
12.2.1.3.0
oracle/business_process_management_suite
12.2.1.4.0
oracle/communications_messaging_server
8.0.2
oracle/communications_messaging_server
8.1
oracle/flexcube_private_banking
12.0.0
oracle/flexcube_private_banking
12.1.0
org.apache.tika/tika
1.0 - 1.24Maven
Published
Mar 23, 2020
Tracked Since
Feb 18, 2026