Resource exhaustion in Apache Commons Compress - CVE-2012-2098

 

Resource exhaustion in Apache Commons Compress - CVE-2012-2098

Published: March 31, 2023


Vulnerability identifier: #VU74271
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-2098
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to algorithmic complexity in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream). A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Apache Commons Compress
Voice Gateway
SecureTransport
webMethods BPM
User Entity Behavior Analytics
Log Analysis
IBM Cloud Pak for Data System
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
watsonx.data
IBM InfoSphere Information Server

How to mitigate CVE-2012-2098

Install updates from vendor's website.

Apache Commons Compress - update to 1.4.1
Voice Gateway - update to 1.0.8.19
SecureTransport - update to 5.5-20220825
webMethods BPM - update to 11.1 Fix 9
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
watsonx.data - update to 2.0.2
IBM Cloud Pak for Data System - update to 2.0.2.1
User Entity Behavior Analytics - update to 5.0.2
IBM Spectrum Control - update to 5.4.10.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Security Verify Governance - update to 10.0.2.0.3
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4

External References

Related Security Bulletins