Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12402

Опубликовано: 30 авг. 2019
Источник: debian

Описание

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libcommons-compress-javafixed1.18-3package
libcommons-compress-javafixed1.18-2+deb10u1busterpackage
libcommons-compress-javanot-affectedstretchpackage
libcommons-compress-javanot-affectedjessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2019/08/27/1

  • Fixed in upstream commit: https://gitbox.apache.org/repos/asf?p=commons-compress.git;a=commitdiff;h=4ad5d80a6272e007f64a6ac66829ca189a8093b9;hp=16a0c84e84b93cc8c107b7ff3080bd11317ab581

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

CVSS3: 7.5
redhat
больше 6 лет назад

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

CVSS3: 7.5
nvd
больше 6 лет назад

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

CVSS3: 7.5
github
больше 6 лет назад

Denial of Service in Apache Commons Compress

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость архиватора Apache Commons Compress, связанная с ошибками управления ресурсом, позволяющая нарушителю вызвать отказ в обслуживании