CVE-2019-12402

HIGH

Apache Commons Compress <1.19 - DoS

Title source: llm

Description

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

Exploits (2)

nomisec STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2019-12402-commons-compress-vulnerable
nomisec WRITEUP
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2019-12402-commons-compress-vulnerable

References (30)

... and 10 more

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 62.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-835
Status published
Products (40)
apache/commons_compress 1.15 - 1.18
fedoraproject/fedora 30
fedoraproject/fedora 31
io.github.1tchy.java9modular.org.apache.commons/commons-compress Maven
oracle/banking_payments 14.1.0 - 14.4.0
oracle/banking_platform 2.6.2
oracle/banking_platform 2.7.0
oracle/banking_platform 2.8.0
oracle/banking_platform 2.9.0
oracle/communications_element_manager 8.2.0 - 8.2.2
... and 30 more
Published Aug 30, 2019
Tracked Since Feb 18, 2026