CVE-2019-12402
published 2019-08-30CVE-2019-12402: The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
16.16%
96.6th percentile
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_compress | 1.15 – 1.18 | — |
| apache_software_foundation | apache_commons_compress | — | — |
| atlassian | confluence_data_center | — | — |
| debian | libcommons-compress-java | < libcommons-compress-java 1.18-3 (bookworm) | libcommons-compress-java 1.18-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | banking_payments | 14.1.0 – 14.4.0 | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | communications_element_manager | 8.2.0 – 8.2.2 | — |
| oracle | communications_ip_service_activator | — | — |
| oracle | communications_ip_service_activator | — | — |
| oracle | communications_session_report_manager | 8.2.0 – 8.2.2 | — |
| oracle | communications_session_route_manager | 8.2.0 – 8.2.2 | — |
| oracle | customer_management_and_segmentation_foundation | — | — |
| oracle | essbase | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2019-12402: DoS (Denial of Service) org.apache.commons:commons-compress Dependency in Confluence Data Center and Server
vendor_atlassian·2024-07-16·CVSS 7.5
CVE-2019-12402 [HIGH] CVE-2019-12402: DoS (Denial of Service) org.apache.commons:commons-compress Dependency in Confluence Data Center and Server
CVE-2019-12402: DoS (Denial of Service) org.apache.commons:commons-compress Dependency in Confluence Data Center and Server
DoS (Denial of Service) org.apache.commons:commons-compress Dependency in Confluence Data Center and Server
CVE: CVE-2019-12402
Affected products: Confluence Data Center
Oracle
Oracle Oracle Essbase Risk Matrix: Infrastructure (Apache Commons Compress) — CVE-2019-12402
vendor_oracle·2021-07-15·CVSS 4.1
CVE-2019-12402 [HIGH] Oracle Oracle Essbase Risk Matrix: Infrastructure (Apache Commons Compress) — CVE-2019-12402
Oracle Oracle Essbase Risk Matrix: Infrastructure (Apache Commons Compress) vulnerability
CVE: CVE-2019-12402
CVSS: 4.1
Protocol: HTTP
Remote exploit: No
Affected versions: Adjacent
Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Apache Commons Compress) — CVE-2019-12402
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2019-12402 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Apache Commons Compress) — CVE-2019-12402
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Apache Commons Compress) vulnerability
CVE: CVE-2019-12402
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Party, Financials (Apache Commons Compress) — CVE-2019-12402
vendor_oracle·2021-01-15·CVSS 7.5
CVE-2019-12402 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Party, Financials (Apache Commons Compress) — CVE-2019-12402
Oracle Oracle Financial Services Applications Risk Matrix: Party, Financials (Apache Commons Compress) vulnerability
CVE: CVE-2019-12402
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Risk Matrix: Core (Apache Commons Compress) — CVE-2019-12402
vendor_oracle·2020-10-15·CVSS 7.5
CVE-2019-12402 [HIGH] Oracle Oracle Communications Risk Matrix: Core (Apache Commons Compress) — CVE-2019-12402
Oracle Oracle Communications Risk Matrix: Core (Apache Commons Compress) vulnerability
CVE: CVE-2019-12402
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Commons Compress) — CVE-2019-12402
vendor_oracle·2020-07-15·CVSS 7.5
CVE-2019-12402 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Commons Compress) — CVE-2019-12402
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Commons Compress) vulnerability
CVE: CVE-2019-12402
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache Commons Compress) — CVE-2019-12402
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2019-12402 [HIGH] Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache Commons Compress) — CVE-2019-12402
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache Commons Compress) vulnerability
CVE: CVE-2019-12402
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Red Hat
apache-commons-compress: Infinite loop in name encoding algorithm
vendor_redhat·2019-08-27·CVSS 7.5
CVE-2019-12402 [HIGH] CWE-172 apache-commons-compress: Infinite loop in name encoding algorithm
apache-commons-compress: Infinite loop in name encoding algorithm
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
A resource consumption vulnerability was discovered in apache-commons-compress in the way NioZipEncoding encodes filenames. Applications that use Compress to create archives, with one of the filenames within the archive being controlled by the user, may be vulnerable to this flaw. A remote attacker could exploit this flaw to cause an infinite loop during the archive creation, thus leading to a denial of service.
Statement: This issue does
Debian
CVE-2019-12402: libcommons-compress-java - The file name encoding algorithm used internally in Apache Commons Compress 1.15...
vendor_debian·2019·CVSS 7.5
CVE-2019-12402 [HIGH] CVE-2019-12402: libcommons-compress-java - The file name encoding algorithm used internally in Apache Commons Compress 1.15...
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
Scope: local
bookworm: resolved (fixed in 1.18-3)
bullseye: resolved (fixed in 1.18-3)
forky: resolved (fixed in 1.18-3)
sid: resolved (fixed in 1.18-3)
trixie: resolved (fixed in 1.18-3)
GHSA
Denial of Service in Apache Commons Compress
ghsa·2019-10-11
CVE-2019-12402 [HIGH] CWE-835 Denial of Service in Apache Commons Compress
Denial of Service in Apache Commons Compress
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
OSV
Denial of Service in Apache Commons Compress
osv·2019-10-11
CVE-2019-12402 [HIGH] Denial of Service in Apache Commons Compress
Denial of Service in Apache Commons Compress
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
OSV
CVE-2019-12402: The file name encoding algorithm used internally in Apache Commons Compress 1
osv·2019-08-30·CVSS 7.5
CVE-2019-12402 [HIGH] CVE-2019-12402: The file name encoding algorithm used internally in Apache Commons Compress 1
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12402 apache-commons-compress: Infinite loop in name encoding algorithm [fedora-all]
bugzilla·2019-10-23·CVSS 7.5
CVE-2019-12402 [HIGH] CVE-2019-12402 apache-commons-compress: Infinite loop in name encoding algorithm [fedora-all]
CVE-2019-12402 apache-commons-compress: Infinite loop in name encoding algorithm [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2019-12402 apache-commons-compress: Infinite loop in name encoding algorithm
bugzilla·2019-10-23·CVSS 7.5
CVE-2019-12402 [HIGH] CVE-2019-12402 apache-commons-compress: Infinite loop in name encoding algorithm
CVE-2019-12402 apache-commons-compress: Infinite loop in name encoding algorithm
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
References:
https://lists.apache.org/thread.html/308cc15f1f1dc53e97046fddbac240e6cd16de89a2746cf257be7f5b@%3Cdev.commons.apache.org%3E
https://lists.apache.org/thread.html/54cc4e9fa6b24520135f6fa4724dfb3465bc14703c7dc7e52353a0ea@%3Ccommits.creadur.apache.org%3E
https://bugzilla.redhat.com/show_bug.cgi?id=1761797
Discussion:
Created apache-commons-compress tracking bugs for this issue:
Affects: fedora-all [bug 1764641]
--
Bugzilla
CVE-2019-12402 apache-commons-compress: denial of service vulnerability
bugzilla·2019-10-15·CVSS 7.5
CVE-2019-12402 [HIGH] CVE-2019-12402 apache-commons-compress: denial of service vulnerability
CVE-2019-12402 apache-commons-compress: denial of service vulnerability
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
According to NIST NVD database this issue has high impact.
For more info see: https://nvd.nist.gov/vuln/detail/CVE-2019-12402
Discussion:
We should be able to merge 1.19 from rawhide into stable branches.
I'll look into it later today.
---
FEDORA-2019-da0eac1eb6 has been submitted as an update to Fedora 31. https://bodhi.fedoraproject.org/updates/FEDORA-2019-da0eac1eb6
---
FEDORA-2019-c96a8d12b0 has been submitted as an update
arXiv
PPT4J: Patch Presence Test for Java Binaries
arxiv_fulltext·2024-01-15
PPT4J: Patch Presence Test for Java Binaries
## Abstract
The number of vulnerabilities reported in open source software has increased substantially in recent years. Security patches provide the necessary measures to protect software from attacks and vulnerabilities. In practice, it is difficult to identify whether patches have been integrated into software, especially if we only have binary files. Therefore, the ability to test whether a patch is applied to the target binary, a.k.a. patch presence test, is crucial for practitioners. However, it is challenging to obtain accurate semantic information from patches, which could lead to incorrect results.
In this paper, we propose a new patch presence test framework named ( ). is designed for open-source Java libraries. It takes Java binaries (i.e. bytecode files) as input, extracts sem
arXiv
How well does LLM generate security tests?
arxiv_fulltext·2023-10-03
How well does LLM generate security tests?
How well does LLM generate security tests?
## Abstract
Developers often build software on top of third-party libraries (Libs) to improve programmer productivity and software quality. The libraries may contain vulnerabilities exploitable by hackers to attack the applications (Apps) built on top of them. People refer to such attacks as supply chain attacks, the documented number of which has increased 742% in 2022. People created tools to mitigate such attacks, by scanning the library dependencies of Apps, identifying the usage of vulnerable library versions, and suggesting secure alternatives to vulnerable dependencies. However, recent studies show that many developers do not trust the reports by these tools; they ask for code or evidence to demonstrate how library vulnerabilities lead to
Tenable
Oracle January 2021 Critical Patch Update Includes Fixes for Five Critical WebLogic Flaws (CVE-2021-2109)
blogs_tenable·2021-01-20·CVSS 7.2
[HIGH] Oracle January 2021 Critical Patch Update Includes Fixes for Five Critical WebLogic Flaws (CVE-2021-2109)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://lists.apache.org/thread.html/308cc15f1f1dc53e97046fddbac240e6cd16de89a2746cf257be7f5b%40%3Cdev.commons.apache.org%3Ehttps://lists.apache.org/thread.html/54cc4e9fa6b24520135f6fa4724dfb3465bc14703c7dc7e52353a0ea%40%3Ccommits.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r05cf37c1e1e662e968cfece1102fcd50fe207181fdbf2c30aadfafd3%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/r21d64797914001119d2fc766b88c6da181dc2308d20f14e7a7f46117%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r233267e24519bacd0f9fb9f61a1287cb9f4bcb6e75d83f34f405c521%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r25422df9ad22fec56d9eeca3ab8bd6d66365e9f6bfe311b64730edf5%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r4363c994c8bca033569a98da9218cc0c62bb695c1e47a98e5084e5a0%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r5103b1c9242c0f812ac96e524344144402cbff9b6e078d1557bc7b1e%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r590c15cebee9b8e757e2f738127a9a71e48ede647a3044c504e050a4%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r5caf4fcb69d2749225391e61db7216282955204849ba94f83afe011f%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r7af60fbd8b2350d49d14e53a3ab2801998b9d1af2d6fcac60b060a53%40%3Cdev.brooklyn.apache.org%3Ehttps://lists.apache.org/thread.html/r972f82d821b805d04602976a9736c01b6bf218cfe0c3f48b472db488%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rcc35ab6be300365de5ff9587e0479d10d7d7c79070921837e3693162%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rd3f99d732baed459b425fb0a9e9e14f7843c9459b12037e4a9d753b5%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rdebc1830d6c09c11d5a4804ca26769dbd292d17d361c61dea50915f0%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/re13bd219dd4b651134f6357f12bd07a0344eea7518c577bbdd185265%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rf5230a049d989dbfdd404b4320a265dceeeba459a4d04ec21873bd55%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLJIK2AUOZOWXR3S5XXBUNMOF3RTHTI7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZB3GB7YXIOUKIOQ27VTIP6KKGJJ3CKL/https://security.netapp.com/advisory/ntap-20230818-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://lists.apache.org/thread.html/308cc15f1f1dc53e97046fddbac240e6cd16de89a2746cf257be7f5b%40%3Cdev.commons.apache.org%3Ehttps://lists.apache.org/thread.html/54cc4e9fa6b24520135f6fa4724dfb3465bc14703c7dc7e52353a0ea%40%3Ccommits.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r05cf37c1e1e662e968cfece1102fcd50fe207181fdbf2c30aadfafd3%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/r21d64797914001119d2fc766b88c6da181dc2308d20f14e7a7f46117%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r233267e24519bacd0f9fb9f61a1287cb9f4bcb6e75d83f34f405c521%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r25422df9ad22fec56d9eeca3ab8bd6d66365e9f6bfe311b64730edf5%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r4363c994c8bca033569a98da9218cc0c62bb695c1e47a98e5084e5a0%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r5103b1c9242c0f812ac96e524344144402cbff9b6e078d1557bc7b1e%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r590c15cebee9b8e757e2f738127a9a71e48ede647a3044c504e050a4%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r5caf4fcb69d2749225391e61db7216282955204849ba94f83afe011f%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r7af60fbd8b2350d49d14e53a3ab2801998b9d1af2d6fcac60b060a53%40%3Cdev.brooklyn.apache.org%3Ehttps://lists.apache.org/thread.html/r972f82d821b805d04602976a9736c01b6bf218cfe0c3f48b472db488%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rcc35ab6be300365de5ff9587e0479d10d7d7c79070921837e3693162%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rd3f99d732baed459b425fb0a9e9e14f7843c9459b12037e4a9d753b5%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rdebc1830d6c09c11d5a4804ca26769dbd292d17d361c61dea50915f0%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/re13bd219dd4b651134f6357f12bd07a0344eea7518c577bbdd185265%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rf5230a049d989dbfdd404b4320a265dceeeba459a4d04ec21873bd55%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLJIK2AUOZOWXR3S5XXBUNMOF3RTHTI7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZB3GB7YXIOUKIOQ27VTIP6KKGJJ3CKL/https://security.netapp.com/advisory/ntap-20230818-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2019-08-30
Published