CVE-2012-2098
published 2012-06-29CVE-2012-2098: Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
12.61%
95.8th percentile
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_compress | < 1.4.1 | 1.4.1 |
| apache | commons_compress | >= 1.22 < 1.24.0 | 1.24.0 |
| apache_software_foundation | apache_commons_compress | >= 1.22 < 1.24.0 | 1.24.0 |
| debian | libcommons-compress-java | < libcommons-compress-java 1.24.0-1 (forky) | libcommons-compress-java 1.24.0-1 (forky) |
| debian | libcommons-compress-java | < libcommons-compress-java 1.4.1-1 (bookworm) | libcommons-compress-java 1.4.1-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
apache-commons-compress: Denial of service via CPU consumption for malformed TAR file
vendor_redhat·2023-09-02·CVSS 5.0
CVE-2023-42503 [MEDIUM] apache-commons-compress: Denial of service via CPU consumption for malformed TAR file
apache-commons-compress: Denial of service via CPU consumption for malformed TAR file
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0.
Users are recommended to upgrade to version 1.24.0, which fixes the issue.
A third party can create a malformed TAR file by manipulating file modification times headers, which when parsed with Apache Commons Compress, will cause a denial of service issue via CPU consumption.
In version 1.22 of Apache Commons Compress, support was added for file modification times with higher precision (issue # COMPRESS-612 [1]). The format for the PAX extended headers carrying this data consists of two numbers separated by a period [2], i
Debian
CVE-2023-42503: libcommons-compress-java - Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Ap...
vendor_debian·2023·CVSS 5.0
CVE-2023-42503 [MEDIUM] CVE-2023-42503: libcommons-compress-java - Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Ap...
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0. Users are recommended to upgrade to version 1.24.0, which fixes the issue. A third party can create a malformed TAR file by manipulating file modification times headers, which when parsed with Apache Commons Compress, will cause a denial of service issue via CPU consumption. In version 1.22 of Apache Commons Compress, support was added for file modification times with higher precision (issue # COMPRESS-612 [1]). The format for the PAX extended headers carrying this data consists of two numbers separated by a period [2], indicating seconds and subsecond precision (for example “1647221103.5998539”). The impac
Red Hat
apache-commons-compress: denial of service flaw when compressing certain files
vendor_redhat·2012-05-23·CVSS 5.0
CVE-2012-2098 [MEDIUM] apache-commons-compress: denial of service flaw when compressing certain files
apache-commons-compress: denial of service flaw when compressing certain files
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
Statement: This issue does not affect the Apache commons-compress library as shipped with JBoss Enterprise BRMS Platform 5.2.0 or JBoss Enterprise Portal Platform 5.2.0.
Package: ant (Red Hat Enterprise Linux 5) - Will not fix
Package: ant (Red Hat Enterprise Linux 6) - Will not fix
Package: Security (Red Hat JBoss BRMS 5) - Not affected
Package: Portal (Red Hat JBoss Portal 5) - Not affected
Debian
CVE-2012-2098: libcommons-compress-java - Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compress...
vendor_debian·2012·CVSS 5.0
CVE-2012-2098 [MEDIUM] CVE-2012-2098: libcommons-compress-java - Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compress...
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
Scope: local
bookworm: resolved (fixed in 1.4.1-1)
bullseye: resolved (fixed in 1.4.1-1)
forky: resolved (fixed in 1.4.1-1)
sid: resolved (fixed in 1.4.1-1)
trixie: resolved (fixed in 1.4.1-1)
VulDB
Apache Commons-compress up to 1.4 cryptographic issue (EUVD-2022-2784 / Nessus ID 72061)
vuldb·2026-04-28·CVSS 5.0
CVE-2012-2098 [MEDIUM] Apache Commons-compress up to 1.4 cryptographic issue (EUVD-2022-2784 / Nessus ID 72061)
A vulnerability classified as problematic has been found in Apache Commons-compress 1.0/1.1/1.2/1.3/1.4. This affects an unknown part. The manipulation leads to cryptographic issues.
This vulnerability is documented as CVE-2012-2098. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
OSV
Apache Commons Compress denial of service vulnerability
osv·2023-09-14·CVSS 5.0
CVE-2023-42503 [MEDIUM] Apache Commons Compress denial of service vulnerability
Apache Commons Compress denial of service vulnerability
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0.
Users are recommended to upgrade to version 1.24.0, which fixes the issue.
A third party can create a malformed TAR file by manipulating file modification times headers, which when parsed with Apache Commons Compress, will cause a denial of service issue via CPU consumption.
In version 1.22 of Apache Commons Compress, support was added for file modification times with higher precision (issue # COMPRESS-612 [1]). The format for the PAX extended headers carrying this data consists of two numbers separated by a period [2], indicating seconds and subse
OSV
CVE-2023-42503: Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing
osv·2023-09-14·CVSS 5.0
CVE-2023-42503 [MEDIUM] CVE-2023-42503: Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0. Users are recommended to upgrade to version 1.24.0, which fixes the issue. A third party can create a malformed TAR file by manipulating file modification times headers, which when parsed with Apache Commons Compress, will cause a denial of service issue via CPU consumption. In version 1.22 of Apache Commons Compress, support was added for file modification times with higher precision (issue # COMPRESS-612 [1]). The format for the PAX extended headers carrying this data consists of two numbers separated by a period [2], indicating seconds and subsecond precision (for example “1647221103.5998539”). The impac
GHSA
Apache Commons Compress denial of service vulnerability
ghsa·2023-09-14·CVSS 5.0
CVE-2023-42503 [MEDIUM] CWE-20 Apache Commons Compress denial of service vulnerability
Apache Commons Compress denial of service vulnerability
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0.
Users are recommended to upgrade to version 1.24.0, which fixes the issue.
A third party can create a malformed TAR file by manipulating file modification times headers, which when parsed with Apache Commons Compress, will cause a denial of service issue via CPU consumption.
In version 1.22 of Apache Commons Compress, support was added for file modification times with higher precision (issue # COMPRESS-612 [1]). The format for the PAX extended headers carrying this data consists of two numbers separated by a period [2], indicating seconds and subse
GHSA
Uncontrolled Resource Consumption in Apache Commons Compress
ghsa·2022-05-13
CVE-2012-2098 [MEDIUM] CWE-400 Uncontrolled Resource Consumption in Apache Commons Compress
Uncontrolled Resource Consumption in Apache Commons Compress
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
OSV
Uncontrolled Resource Consumption in Apache Commons Compress
osv·2022-05-13
CVE-2012-2098 [MEDIUM] Uncontrolled Resource Consumption in Apache Commons Compress
Uncontrolled Resource Consumption in Apache Commons Compress
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
OSV
CVE-2012-2098: Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress be
osv·2012-06-29·CVSS 5.0
CVE-2012-2098 [MEDIUM] CVE-2012-2098: Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress be
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2098 apache-commons-compress: denial of service flaw when compressing certain files [fedora-all]
bugzilla·2012-05-24·CVSS 5.0
CVE-2012-2098 [MEDIUM] CVE-2012-2098 apache-commons-compress: denial of service flaw when compressing certain files [fedora-all]
CVE-2012-2098 apache-commons-compress: denial of service flaw when compressing certain files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.o
Bugzilla
CVE-2012-2098 apache-commons-compress: denial of service flaw when compressing certain files
bugzilla·2012-04-05·CVSS 5.0
CVE-2012-2098 [MEDIUM] CVE-2012-2098 apache-commons-compress: denial of service flaw when compressing certain files
CVE-2012-2098 apache-commons-compress: denial of service flaw when compressing certain files
A flaw was found in the Apache commons-compress Java library when compressing files using bzip2 compression. If a malicious user were to provide a specially-crafted file to a service using commons-compress, it would take an extremely long time to compress the file, which could possibly lead to a denial of service.
Discussion:
apache-commons-compress is shipped with JBoss Enterprise BRMS Platform 5.2.0. It is only used in the org.jbpm.process.workitem.archive.ArchiveWorkItemHandler class, which does not utilize bzip2 compression. Therefore JBoss Enterprise BRMS Platform 5.2.0 is not affected by this flaw.
---
apache-commons-compress is shipped with JBoss Enterprise Portal Platform 5.2.0. The JA
arXiv
Impact assessment for vulnerabilities in open-source software libraries
arxiv_fulltext·2015-04-21
Impact assessment for vulnerabilities in open-source software libraries
fancy
Software applications integrate more and more open-source software
(OSS) to benefit from code reuse. As a drawback, each vulnerability
discovered in bundled OSS potentially affects the application. Upon
the disclosure of every new vulnerability, the application vendor has
to decide whether it is exploitable in his particular usage context,
hence, whether users require an urgent application patch containing a
non-vulnerable version of the OSS. Current decision making is mostly
based on high-level vulnerability descriptions and expert knowledge,
thus, effort intense and error prone. This paper proposes a pragmatic
approach to facilitate the impact assessment, describes a
proof-of-concept for Java, and examines one example vulnerability as
case study. The approach is independent from s
http://ant.apache.org/security.htmlhttp://archives.neohapsis.com/archives/bugtraq/2012-05/0130.htmlhttp://commons.apache.org/compress/security.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/081697.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/081746.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105049.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105060.htmlhttp://osvdb.org/82161http://packetstormsecurity.org/files/113014/Apache-Commons-Compress-Apache-Ant-Denial-Of-Service.htmlhttp://secunia.com/advisories/49255http://secunia.com/advisories/49286http://www-01.ibm.com/support/docview.wss?uid=swg21644047http://www.openwall.com/lists/oss-security/2023/09/13/3http://www.securityfocus.com/bid/53676http://www.securitytracker.com/id?1027096https://exchange.xforce.ibmcloud.com/vulnerabilities/75857https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujan2021.htmlhttp://ant.apache.org/security.htmlhttp://archives.neohapsis.com/archives/bugtraq/2012-05/0130.htmlhttp://commons.apache.org/compress/security.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/081697.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/081746.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105049.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105060.htmlhttp://osvdb.org/82161http://packetstormsecurity.org/files/113014/Apache-Commons-Compress-Apache-Ant-Denial-Of-Service.htmlhttp://secunia.com/advisories/49255http://secunia.com/advisories/49286http://www-01.ibm.com/support/docview.wss?uid=swg21644047http://www.openwall.com/lists/oss-security/2023/09/13/3http://www.securityfocus.com/bid/53676http://www.securitytracker.com/id?1027096https://exchange.xforce.ibmcloud.com/vulnerabilities/75857https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujan2021.html
2012-06-29
Published