cbcvebase.
CVE-2019-12402
published 2019-08-30

CVE-2019-12402: The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
apachecommons_compress1.15 – 1.18
apache_software_foundationapache_commons_compress
atlassianconfluence_data_center
debianlibcommons-compress-java< libcommons-compress-java 1.18-3 (bookworm)libcommons-compress-java 1.18-3 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
oraclebanking_payments14.1.0 – 14.4.0
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclecommunications_element_manager8.2.0 – 8.2.2
oraclecommunications_ip_service_activator
oraclecommunications_ip_service_activator
oraclecommunications_session_report_manager8.2.0 – 8.2.2
oraclecommunications_session_route_manager8.2.0 – 8.2.2
oraclecustomer_management_and_segmentation_foundation
oracleessbase
oracleflexcube_investor_servicing
oracleflexcube_investor_servicing
oracleflexcube_investor_servicing
oracleflexcube_investor_servicing
oracleflexcube_investor_servicing
oracleflexcube_private_banking
oracleflexcube_private_banking

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH