CVE Vulnerabilities

CVE-2019-20421

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jan 27, 2020 | Modified: Sep 14, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Exiv2 Exiv2 0.27.2 (including) 0.27.2 (including)
Red Hat Enterprise Linux 8 RedHat exiv2-0:0.27.2-5.el8 *
Red Hat Enterprise Linux 8 RedHat gegl-0:0.2.0-39.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-color-manager-0:3.28.0-3.el8 *
Red Hat Enterprise Linux 8 RedHat libgexiv2-0:0.10.8-4.el8 *
Exiv2 Ubuntu bionic *
Exiv2 Ubuntu devel *
Exiv2 Ubuntu eoan *
Exiv2 Ubuntu trusty *
Exiv2 Ubuntu upstream *
Exiv2 Ubuntu xenial *

References