Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-53x6-4x5p-rrvv

Опубликовано: 11 окт. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of Service in Apache Commons Compress

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

Ссылки

Пакеты

Наименование

org.apache.commons:commons-compress

maven
Затронутые версииВерсия исправления

>= 1.15, < 1.19

1.19

Наименование

io.github.1tchy.java9modular.org.apache.commons:commons-compress

maven
Затронутые версииВерсия исправления

= 1.18.1

Отсутствует

EPSS

Процентиль: 59%
0.00382
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

CVSS3: 7.5
redhat
больше 6 лет назад

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

CVSS3: 7.5
nvd
больше 6 лет назад

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

CVSS3: 7.5
debian
больше 6 лет назад

The file name encoding algorithm used internally in Apache Commons Com ...

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость архиватора Apache Commons Compress, связанная с ошибками управления ресурсом, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 59%
0.00382
Низкий

7.5 High

CVSS3

Дефекты

CWE-835