Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12402

Опубликовано: 27 авг. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

A resource consumption vulnerability was discovered in apache-commons-compress in the way NioZipEncoding encodes filenames. Applications that use Compress to create archives, with one of the filenames within the archive being controlled by the user, may be vulnerable to this flaw. A remote attacker could exploit this flaw to cause an infinite loop during the archive creation, thus leading to a denial of service.

Отчет

This issue does not affect the versions of apache-commons-compress as shipped with Red Hat Enterprise Linux 7, and the versions of rh-java-common-apache-commons-compress and rh-maven35-apache-commons-compress as shipped with Red Hat Software Collections 3, as they used a fallback zip encoding implementation (leveraging java.io) to encode filenames. This issue does not affect the versions of rh-maven36-apache-commons-compress as shipped with Red Hat Software Collection 3 as they already include the patch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2apache-commons-compressNot affected
Red Hat BPM Suite 6apache-commons-compressNot affected
Red Hat Data Grid 8apache-commons-compressNot affected
Red Hat Decision Manager 7apache-commons-compressNot affected
Red Hat Enterprise Linux 7apache-commons-compressNot affected
Red Hat Integration Camel K 1apache-commons-compressNot affected
Red Hat Integration Service Registryapache-commons-compressNot affected
Red Hat JBoss BRMS 6apache-commons-compressNot affected
Red Hat JBoss Data Virtualization 6apache-commons-compressOut of support scope
Red Hat JBoss Enterprise Application Platform 6apache-commons-compressNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-172->CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1764640apache-commons-compress: Infinite loop in name encoding algorithm

EPSS

Процентиль: 59%
0.00382
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

CVSS3: 7.5
nvd
больше 6 лет назад

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

CVSS3: 7.5
debian
больше 6 лет назад

The file name encoding algorithm used internally in Apache Commons Com ...

CVSS3: 7.5
github
больше 6 лет назад

Denial of Service in Apache Commons Compress

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость архиватора Apache Commons Compress, связанная с ошибками управления ресурсом, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 59%
0.00382
Низкий

7.5 High

CVSS3