VYPR
Medium severity5.5OSV Advisory· Published Mar 23, 2020· Updated Jun 17, 2026

CVE-2020-1951

CVE-2020-1951

Description

A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.tika:tikaMaven
>= 1.0, < 1.241.24

Affected products

11
  • Apache/TikaOSV2 versions
    (expand)+ 1 more
    • (no CPE)
    • cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*range: >=1.0,<=1.23
  • cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:communications_messaging_server:8.0.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:communications_messaging_server:8.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 1.0, < 1.24

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.