← Back

CVE-2019-12402

nvd nist
Published: Aug 30, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

Affected (38)

1 product
Commons Compress
1 product
Fedora
17 products
Banking Payments
Banking Platform
Communications Element Manager
Essbase
Flexcube Investor Servicing
Flexcube Private Banking
Jdeveloper
Primavera Gateway
Retail Integration Bus
Retail Xstore Point Of Service
Webcenter Portal
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.15 to 1.18
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31
Configuration C
35 vulnerable
Vulnerable SoftwareAffected Versions
From 14.1.0 to 14.4.0
Oracle
Version 2.6.2
Version 2.7.0
Version 2.8.0
Version 2.9.0
From 8.2.0 to 8.2.2
Oracle
Version 7.3.0
Version 7.4.0
From 8.2.0 to 8.2.2
From 8.2.0 to 8.2.2
Version 18.0
Version 21.2
Oracle
Version 12.1.0
Version 12.3.0
Version 12.4.0
Version 14.0.0
Version 14.1.0
Oracle
Version 12.0.0
Version 12.1.0
Version 11.1.2.4
Version 12.2.1.4.0
Oracle
Version 8.56
Version 8.57
Version 8.58
Oracle
From 18.8.0 to 18.8.8
Version 19.12.0
Oracle
Version 15.0
Version 16.0
Oracle
Version 15.0
Version 16.0
Version 17.0
Version 18.0
Version 19.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0

References (60)

Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory

Timeline

No history available yet.