// For flags

CVE-2019-12402

apache-commons-compress: Infinite loop in name encoding algorithm

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

El algoritmo de codificación de nombre de archivo utilizado internamente en Apache Commons Compress versiones 1.15 hasta 1.18, puede entrar en un bucle infinito cuando se enfrenta a entradas especialmente diseñadas. Esto puede conllevar a un ataque de denegación de servicio si un atacante puede elegir los nombres de archivo dentro de un registro creado por Compress.

A resource consumption vulnerability was discovered in apache-commons-compress in the way NioZipEncoding encodes filenames. Applications that use Compress to create archives, with one of the filenames within the archive being controlled by the user, may be vulnerable to this flaw. A remote attacker could exploit this flaw to cause an infinite loop during the archive creation, thus leading to a denial of service.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-05-28 CVE Reserved
  • 2019-08-29 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
CAPEC
References (32)
URL Tag Source
https://lists.apache.org/thread.html/308cc15f1f1dc53e97046fddbac240e6cd16de89a2746cf257be7f5b%40%3Cdev.commons.apache.org%3E
https://lists.apache.org/thread.html/54cc4e9fa6b24520135f6fa4724dfb3465bc14703c7dc7e52353a0ea%40%3Ccommits.creadur.apache.org%3E Mailing List
https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r05cf37c1e1e662e968cfece1102fcd50fe207181fdbf2c30aadfafd3%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r21d64797914001119d2fc766b88c6da181dc2308d20f14e7a7f46117%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r233267e24519bacd0f9fb9f61a1287cb9f4bcb6e75d83f34f405c521%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r25422df9ad22fec56d9eeca3ab8bd6d66365e9f6bfe311b64730edf5%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r4363c994c8bca033569a98da9218cc0c62bb695c1e47a98e5084e5a0%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r5103b1c9242c0f812ac96e524344144402cbff9b6e078d1557bc7b1e%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r590c15cebee9b8e757e2f738127a9a71e48ede647a3044c504e050a4%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r5caf4fcb69d2749225391e61db7216282955204849ba94f83afe011f%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r7af60fbd8b2350d49d14e53a3ab2801998b9d1af2d6fcac60b060a53%40%3Cdev.brooklyn.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r972f82d821b805d04602976a9736c01b6bf218cfe0c3f48b472db488%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/rcc35ab6be300365de5ff9587e0479d10d7d7c79070921837e3693162%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/rd3f99d732baed459b425fb0a9e9e14f7843c9459b12037e4a9d753b5%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/rdebc1830d6c09c11d5a4804ca26769dbd292d17d361c61dea50915f0%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/re13bd219dd4b651134f6357f12bd07a0344eea7518c577bbdd185265%40%3Cissues.flink.apache.org%3E Mailing List
https://lists.apache.org/thread.html/rf5230a049d989dbfdd404b4320a265dceeeba459a4d04ec21873bd55%40%3Csolr-user.lucene.apache.org%3E Mailing List
https://security.netapp.com/advisory/ntap-20230818-0001
https://www.oracle.com//security-alerts/cpujul2021.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Not Applicable
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Commons Compress
Search vendor "Apache" for product "Commons Compress"
>= 1.15 <= 1.18
Search vendor "Apache" for product "Commons Compress" and version " >= 1.15 <= 1.18"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
30
Search vendor "Fedoraproject" for product "Fedora" and version "30"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
31
Search vendor "Fedoraproject" for product "Fedora" and version "31"
-
Affected
Oracle
Search vendor "Oracle"
Banking Payments
Search vendor "Oracle" for product "Banking Payments"
>= 14.1.0 <= 14.4.0
Search vendor "Oracle" for product "Banking Payments" and version " >= 14.1.0 <= 14.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.6.2
Search vendor "Oracle" for product "Banking Platform" and version "2.6.2"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.7.0
Search vendor "Oracle" for product "Banking Platform" and version "2.7.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.8.0
Search vendor "Oracle" for product "Banking Platform" and version "2.8.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.9.0
Search vendor "Oracle" for product "Banking Platform" and version "2.9.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Element Manager
Search vendor "Oracle" for product "Communications Element Manager"
>= 8.2.0 <= 8.2.2
Search vendor "Oracle" for product "Communications Element Manager" and version " >= 8.2.0 <= 8.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Ip Service Activator
Search vendor "Oracle" for product "Communications Ip Service Activator"
7.3.0
Search vendor "Oracle" for product "Communications Ip Service Activator" and version "7.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Ip Service Activator
Search vendor "Oracle" for product "Communications Ip Service Activator"
7.4.0
Search vendor "Oracle" for product "Communications Ip Service Activator" and version "7.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Session Report Manager
Search vendor "Oracle" for product "Communications Session Report Manager"
>= 8.2.0 <= 8.2.2
Search vendor "Oracle" for product "Communications Session Report Manager" and version " >= 8.2.0 <= 8.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Session Route Manager
Search vendor "Oracle" for product "Communications Session Route Manager"
>= 8.2.0 <= 8.2.2
Search vendor "Oracle" for product "Communications Session Route Manager" and version " >= 8.2.0 <= 8.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Customer Management And Segmentation Foundation
Search vendor "Oracle" for product "Customer Management And Segmentation Foundation"
18.0
Search vendor "Oracle" for product "Customer Management And Segmentation Foundation" and version "18.0"
-
Affected
Oracle
Search vendor "Oracle"
Essbase
Search vendor "Oracle" for product "Essbase"
21.2
Search vendor "Oracle" for product "Essbase" and version "21.2"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Investor Servicing
Search vendor "Oracle" for product "Flexcube Investor Servicing"
12.1.0
Search vendor "Oracle" for product "Flexcube Investor Servicing" and version "12.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Investor Servicing
Search vendor "Oracle" for product "Flexcube Investor Servicing"
12.3.0
Search vendor "Oracle" for product "Flexcube Investor Servicing" and version "12.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Investor Servicing
Search vendor "Oracle" for product "Flexcube Investor Servicing"
12.4.0
Search vendor "Oracle" for product "Flexcube Investor Servicing" and version "12.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Investor Servicing
Search vendor "Oracle" for product "Flexcube Investor Servicing"
14.0.0
Search vendor "Oracle" for product "Flexcube Investor Servicing" and version "14.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Investor Servicing
Search vendor "Oracle" for product "Flexcube Investor Servicing"
14.1.0
Search vendor "Oracle" for product "Flexcube Investor Servicing" and version "14.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
12.0.0
Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
12.1.0
Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Hyperion Infrastructure Technology
Search vendor "Oracle" for product "Hyperion Infrastructure Technology"
11.1.2.4
Search vendor "Oracle" for product "Hyperion Infrastructure Technology" and version "11.1.2.4"
-
Affected
Oracle
Search vendor "Oracle"
Jdeveloper
Search vendor "Oracle" for product "Jdeveloper"
12.2.1.4.0
Search vendor "Oracle" for product "Jdeveloper" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Pt Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Pt Peopletools"
8.56
Search vendor "Oracle" for product "Peoplesoft Enterprise Pt Peopletools" and version "8.56"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Pt Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Pt Peopletools"
8.57
Search vendor "Oracle" for product "Peoplesoft Enterprise Pt Peopletools" and version "8.57"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Pt Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Pt Peopletools"
8.58
Search vendor "Oracle" for product "Peoplesoft Enterprise Pt Peopletools" and version "8.58"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
>= 18.8.0 <= 18.8.8
Search vendor "Oracle" for product "Primavera Gateway" and version " >= 18.8.0 <= 18.8.8"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
19.12.0
Search vendor "Oracle" for product "Primavera Gateway" and version "19.12.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
15.0
Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
16.0
Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
15.0
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
16.0
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
17.0
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "17.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
18.0
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "18.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
19.0
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "19.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.3.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.4.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.4.0"
-
Affected