Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-12402

Опубликовано: 30 авг. 2019
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 5
CVSS3: 7.5

Описание

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1.18-3
disco

ignored

end of life
eoan

not-affected

1.18-3
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

needed

esm-apps/focal

not-affected

1.18-3
esm-apps/jammy

not-affected

1.18-3
esm-apps/noble

not-affected

1.18-3
esm-apps/resolute

not-affected

1.18-3

Показывать по

EPSS

Процентиль: 97%
0.16157
Средний

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 7 лет назад

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

CVSS3: 7.5
nvd
почти 7 лет назад

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

CVSS3: 7.5
debian
почти 7 лет назад

The file name encoding algorithm used internally in Apache Commons Com ...

CVSS3: 7.5
github
почти 7 лет назад

Denial of Service in Apache Commons Compress

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость архиватора Apache Commons Compress, связанная с ошибками управления ресурсом, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 97%
0.16157
Средний

5 Medium

CVSS2

7.5 High

CVSS3

Уязвимость CVE-2019-12402