Medium severity5.5OSV Advisory· Published Mar 23, 2020· Updated Jun 17, 2026
CVE-2020-1951
CVE-2020-1951
Description
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tika:tikaMaven | >= 1.0, < 1.24 | 1.24 |
Affected products
11cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_messaging_server:8.0.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:communications_messaging_server:8.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
Patches
Vulnerability mechanics
References
8- www.oracle.com/security-alerts/cpujul2020.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2020.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-3264-3fm9-fg44ghsaADVISORY
- lists.apache.org/thread.html/rd8c1b42bd0e31870d804890b3f00b13d837c528f7ebaf77031323172%40%3Cdev.tika.apache.org%3EnvdMailing ListVendor AdvisoryWEB
- lists.debian.org/debian-lts-announce/2020/03/msg00035.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-1951ghsaADVISORY
- usn.ubuntu.com/4564-1/nvdThird Party Advisory
- usn.ubuntu.com/4564-1ghsaWEB
News mentions
0No linked articles in our index yet.