Junglewise Threat Intelligence

PYSEC-2020-344 - In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumptio

Severity: low · CVSS 3.1 · Published 2020-01-27

Technologies: exiv2 (PyPI). Vendors: PyPI.

Executive brief

In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

Affected products

  • PyPI exiv2

Related threats