UBUNTU-CVE-2019-12402
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-12402
Summary:
Details: The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
References: https://ubuntu.com/security/CVE-2019-12402, https://www.openwall.com/lists/oss-security/2019/08/27/1, https://lists.apache.org/thread.html/308cc15f1f1dc53e97046fddbac240e6cd16de89a2746cf257be7f5b@%3Cdev.commons.apache.org%3E, https://www.cve.org/CVERecord?id=CVE-2019-12402
Affected packages
Package
Name: libcommons-compress-java
Purl: pkg:deb/ubuntu/[email protected]~18.04?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
