{"id":"MGASA-2020-0084","summary":"Updated exiv2 packages fix security vulnerability","details":"The updated packages fix a security vulnerability:\n\nIn Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file\ncan result in an infinite loop and hang, with high CPU consumption. Remote\nattackers could leverage this vulnerability to cause a denial of service\nvia a crafted file. (CVE-2019-20421)\n","modified":"2026-04-16T00:10:29.746274303Z","published":"2020-02-13T10:49:00Z","upstream":["CVE-2019-20421"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0084.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26171"},{"type":"WEB","url":"https://usn.ubuntu.com/4270-1/"}],"affected":[{"package":{"name":"exiv2","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/exiv2?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.27.1-3.3.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0084.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}