Resource management error in Apache Commons Compress - CVE-2019-12402

 

Resource management error in Apache Commons Compress - CVE-2019-12402

Published: October 23, 2019 / Updated: July 29, 2024


Vulnerability identifier: #VU22185
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12402
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the file name encoding algorithm can get into an infinite loop when faced with specially crafted inputs. A remote attacker can choose the file names inside of an archive created by Compress and cause a denial of service condition on the target system.


Affected software

Apache Commons Compress
IBM PureData System for Operational Analytics
Confluence Data Center
Oracle Communications Session Report Manager
Infrastructure Technology
Oracle Banking Platform
Oracle FLEXCUBE Investor Servicing
Confluence Server
Oracle Communications Element Manager
Oracle Communications Session Route Manager
Oracle WebCenter Portal
Oracle JDeveloper
Primavera Gateway
Oracle Essbase
Fedora
apache-commons-compress
Operational Decision Manager

How to mitigate CVE-2019-12402

Install updates from vendor's website.

Apache Commons Compress - update to 1.19
Confluence Server - addressed in versions 7.19.25, 8.5.12
Confluence Data Center - addressed in versions 7.19.25, 8.5.12, 8.9.4
Primavera Gateway - update to 18.8.8.1
apache-commons-compress - addressed in versions 1.19-1.fc30, 1.19-1.fc31
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10

External References

Related Security Bulletins