CVE-2020-1950

A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_messaging_server:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

07 Oct 2022, 01:59

Type Values Removed Values Added
First Time Oracle flexcube Private Banking
Canonical ubuntu Linux
Oracle business Process Management Suite
Canonical
Debian debian Linux
Oracle
Debian
Oracle communications Messaging Server
References (MLIST) https://lists.debian.org/debian-lts-announce/2020/03/msg00035.html - (MLIST) https://lists.debian.org/debian-lts-announce/2020/03/msg00035.html - Mailing List, Third Party Advisory
References (UBUNTU) https://usn.ubuntu.com/4564-1/ - (UBUNTU) https://usn.ubuntu.com/4564-1/ - Third Party Advisory
References (MISC) https://www.oracle.com/security-alerts/cpuoct2020.html - (MISC) https://www.oracle.com/security-alerts/cpuoct2020.html - Patch, Third Party Advisory
References (MISC) https://www.oracle.com/security-alerts/cpujul2020.html - (MISC) https://www.oracle.com/security-alerts/cpujul2020.html - Patch, Third Party Advisory
CPE cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_messaging_server:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*

Information

Published : 2020-03-23 14:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-1950

Mitre link : CVE-2020-1950

CVE.ORG link : CVE-2020-1950


JSON object : View

Products Affected

oracle

  • flexcube_private_banking
  • business_process_management_suite
  • communications_messaging_server

apache

  • tika

debian

  • debian_linux

canonical

  • ubuntu_linux
CWE
CWE-400

Uncontrolled Resource Consumption