Exiv2 · Exiv2 · CVE-2019-20421
**Name of the Vulnerable Software and Affected Versions**
Exiv2 version 0.27.2
**Description**
The issue is related to the incorrect handling of input files by the Jp2Image::readMetadata() function in the Exiv2 library, which manages media file metadata. This can lead to an infinite loop and high CPU consumption when processing a crafted file. Remote attackers could exploit this to cause a denial of service.
**Recommendations**
For Exiv2 version 0.27.2, consider disabling the `Jp2Image::readMetadata()` function until a patch is available to prevent potential denial of service attacks via crafted files.