A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "16.04"
}
],
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "canonical:ubuntu_linux"
},
{
"extracted_events": [
{
"last_affected": "8.0"
}
],
"source": "CPE_STRING",
"vendor_product": "debian:debian_linux",
"cpes": [
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:business_process_management_suite"
},
{
"extracted_events": [
{
"last_affected": "8.0.2"
},
{
"last_affected": "8.1"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_messaging_server:8.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_messaging_server"
},
{
"extracted_events": [
{
"last_affected": "12.0.0"
},
{
"last_affected": "12.1.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:flexcube_private_banking"
}
]
}