The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2019-08-30 02:15
Updated : 2022-05-13 20:15
NVD link : CVE-2019-12402
Mitre link : CVE-2019-12402
JSON object : View
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
Products Affected
oracle
- webcenter_portal
- peoplesoft_enterprise_pt_peopletools
- retail_integration_bus
- communications_session_route_manager
- hyperion_infrastructure_technology
- communications_session_report_manager
- essbase
- flexcube_private_banking
- customer_management_and_segmentation_foundation
- banking_platform
- communications_element_manager
- primavera_gateway
- flexcube_investor_servicing
- retail_xstore_point_of_service
- communications_ip_service_activator
- jdeveloper
- banking_payments
fedoraproject
- fedora
apache
- commons_compress