← All CVEs

CVE-2019-12402

high · 7.5

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

7.5
CVSS
16.2%
EPSS (exploit prob.)
97th
EPSS percentile
2019-08-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-835

Affected products

VendorProductAffected versions
apachecommons_compress>= 1.15, <= 1.18
fedoraprojectfedora30
fedoraprojectfedora31
oraclebanking_payments>= 14.1.0, <= 14.4.0
oraclebanking_platform2.6.2
oraclebanking_platform2.7.0
oraclebanking_platform2.8.0
oraclebanking_platform2.9.0
oraclecommunications_element_manager>= 8.2.0, <= 8.2.2
oraclecommunications_ip_service_activator7.3.0
oraclecommunications_ip_service_activator7.4.0
oraclecommunications_session_report_manager>= 8.2.0, <= 8.2.2
oraclecommunications_session_route_manager>= 8.2.0, <= 8.2.2
oraclecustomer_management_and_segmentation_foundation18.0
oracleessbase21.2
oracleflexcube_investor_servicing12.1.0
oracleflexcube_investor_servicing12.3.0
oracleflexcube_investor_servicing12.4.0
oracleflexcube_investor_servicing14.0.0
oracleflexcube_investor_servicing14.1.0
oracleflexcube_private_banking12.0.0
oracleflexcube_private_banking12.1.0
oraclehyperion_infrastructure_technology11.1.2.4
oraclejdeveloper12.2.1.4.0
oraclepeoplesoft_enterprise_pt_peopletools8.56
oraclepeoplesoft_enterprise_pt_peopletools8.57
oraclepeoplesoft_enterprise_pt_peopletools8.58
oracleprimavera_gateway>= 18.8.0, <= 18.8.8
oracleprimavera_gateway19.12.0
oracleretail_integration_bus15.0
oracleretail_integration_bus16.0
oracleretail_xstore_point_of_service15.0
oracleretail_xstore_point_of_service16.0
oracleretail_xstore_point_of_service17.0
oracleretail_xstore_point_of_service18.0
oracleretail_xstore_point_of_service19.0
oraclewebcenter_portal12.2.1.3.0
oraclewebcenter_portal12.2.1.4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-12402