CVE-2019-20421: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 4.3% chance of exploitation in the next 30 days.

In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • EXIV2 EXIV2: version 0.27.2 only

Published 2020-01-27. Last modified 2026-06-17.