apache-commons-compress: Infinite loop in name encoding algorithm
Published Aug 29, 2019
7.5
HIGHCVSS 3.1
EPSS 16.16%
Description
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
Affected products
-
- Version 1.15 to 1.18StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Commons Compress | n/a |
|
Configuration 1
- ≥ 1.15 · ≤ 1.18
Configuration 2
- 30
- 31
Configuration 3
- ≥ 14.1.0 · ≤ 14.4.0
- 2.6.2
- 2.7.0
- 2.8.0
- 2.9.0
- ≥ 8.2.0 · ≤ 8.2.2
- 7.3.0
- 7.4.0
- ≥ 8.2.0 · ≤ 8.2.2
- ≥ 8.2.0 · ≤ 8.2.2
- 18.0
- 21.2
- 12.1.0
- 12.3.0
- 12.4.0
- 14.0.0
- 14.1.0
- 12.0.0
- 12.1.0
- 11.1.2.4
- 12.2.1.4.0
- 8.56
- 8.57
- 8.58
- ≥ 18.8.0 · ≤ 18.8.8
- 19.12.0
- 15.0
- 16.0
- 15.0
- 16.0
- 17.0
- 18.0
- 19.0
- 12.2.1.3.0
- 12.2.1.4.0
No data.
Red Hat Fuse 7.9
apache-commons-compress
Fixed · RHSA-2021:3140
A-MQ Clients 2
apache-commons-compress
Not affected
Red Hat BPM Suite 6
apache-commons-compress
Not affected
Red Hat Data Grid 8
apache-commons-compress
Not affected
Red Hat Decision Manager 7
apache-commons-compress
Not affected
Red Hat Enterprise Linux 7
apache-commons-compress
Not affected
Red Hat Integration Camel K 1
apache-commons-compress
Not affected
Red Hat Integration Service Registry
apache-commons-compress
Not affected
Red Hat JBoss BRMS 6
apache-commons-compress
Not affected
Red Hat JBoss Data Virtualization 6
apache-commons-compress
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
apache-commons-compress
Not affected
Red Hat JBoss Fuse 6
apache-commons-compress
Not affected
Red Hat JBoss Fuse Service Works 6
apache-commons-compress
Not affected
Red Hat Process Automation 7
apache-commons-compress
Not affected
Red Hat Software Collections
rh-java-common-apache-commons-compress
Not affected
Red Hat Software Collections
rh-maven35-apache-commons-compress
Not affected
Red Hat Software Collections
rh-maven36-apache-commons-compress
Not affected
Red Hat Virtualization 4
apache-commons-compress
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.9 | apache-commons-compress | Fixed | RHSA-2021:3140 |
| A-MQ Clients 2 | apache-commons-compress | Not affected | n/a |
| Red Hat BPM Suite 6 | apache-commons-compress | Not affected | n/a |
| Red Hat Data Grid 8 | apache-commons-compress | Not affected | n/a |
| Red Hat Decision Manager 7 | apache-commons-compress | Not affected | n/a |
| Red Hat Enterprise Linux 7 | apache-commons-compress | Not affected | n/a |
| Red Hat Integration Camel K 1 | apache-commons-compress | Not affected | n/a |
| Red Hat Integration Service Registry | apache-commons-compress | Not affected | n/a |
| Red Hat JBoss BRMS 6 | apache-commons-compress | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | apache-commons-compress | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | apache-commons-compress | Not affected | n/a |
| Red Hat JBoss Fuse 6 | apache-commons-compress | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | apache-commons-compress | Not affected | n/a |
| Red Hat Process Automation 7 | apache-commons-compress | Not affected | n/a |
| Red Hat Software Collections | rh-java-common-apache-commons-compress | Not affected | n/a |
| Red Hat Software Collections | rh-maven35-apache-commons-compress | Not affected | n/a |
| Red Hat Software Collections | rh-maven36-apache-commons-compress | Not affected | n/a |
| Red Hat Virtualization 4 | apache-commons-compress | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the versions of apache-commons-compress as shipped with Red Hat Enterprise Linux 7, and the versions of rh-java-common-apache-commons-compress and rh-maven35-apache-commons-compress as shipped with Red Hat Software Collections 3, as they used a fallback zip encoding implementation (leveraging java.io) to encode filenames. This issue does not affect the versions of rh-maven36-apache-commons-compress as shipped with Red Hat Software Collection 3 as they already include the patch.
References (58)
- https://access.redhat.com/security/cve/CVE-2019-12402 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1764640 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0685 Advisory
- https://github.com/advisories/GHSA-53x6-4x5p-rrvv Advisory
- https://github.com/jensdietrich/xshady-release/tree/main/CVE-2019-12402
- https://lists.apache.org/thread.html/308cc15f1f1dc53e97046fddbac240e6cd16de89a2746cf257be7f5b%40%3Cdev.commons.apache.org%3E
- https://lists.apache.org/thread.html/308cc15f1f1dc53e97046fddbac240e6cd16de89a2746cf257be7f5b@%3Cdev.commons.apache.org%3E
- https://lists.apache.org/thread.html/54cc4e9fa6b24520135f6fa4724dfb3465bc14703c7dc7e52353a0ea%40%3Ccommits.creadur.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/54cc4e9fa6b24520135f6fa4724dfb3465bc14703c7dc7e52353a0ea@%3Ccommits.creadur.apache.org%3E
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r05cf37c1e1e662e968cfece1102fcd50fe207181fdbf2c30aadfafd3%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r05cf37c1e1e662e968cfece1102fcd50fe207181fdbf2c30aadfafd3@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r21d64797914001119d2fc766b88c6da181dc2308d20f14e7a7f46117%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r21d64797914001119d2fc766b88c6da181dc2308d20f14e7a7f46117@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r233267e24519bacd0f9fb9f61a1287cb9f4bcb6e75d83f34f405c521%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r233267e24519bacd0f9fb9f61a1287cb9f4bcb6e75d83f34f405c521@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r25422df9ad22fec56d9eeca3ab8bd6d66365e9f6bfe311b64730edf5%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r25422df9ad22fec56d9eeca3ab8bd6d66365e9f6bfe311b64730edf5@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r4363c994c8bca033569a98da9218cc0c62bb695c1e47a98e5084e5a0%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r4363c994c8bca033569a98da9218cc0c62bb695c1e47a98e5084e5a0@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r5103b1c9242c0f812ac96e524344144402cbff9b6e078d1557bc7b1e%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r5103b1c9242c0f812ac96e524344144402cbff9b6e078d1557bc7b1e@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r590c15cebee9b8e757e2f738127a9a71e48ede647a3044c504e050a4%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r590c15cebee9b8e757e2f738127a9a71e48ede647a3044c504e050a4@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r5caf4fcb69d2749225391e61db7216282955204849ba94f83afe011f%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r5caf4fcb69d2749225391e61db7216282955204849ba94f83afe011f@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r7af60fbd8b2350d49d14e53a3ab2801998b9d1af2d6fcac60b060a53%40%3Cdev.brooklyn.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r7af60fbd8b2350d49d14e53a3ab2801998b9d1af2d6fcac60b060a53@%3Cdev.brooklyn.apache.org%3E
- https://lists.apache.org/thread.html/r972f82d821b805d04602976a9736c01b6bf218cfe0c3f48b472db488%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r972f82d821b805d04602976a9736c01b6bf218cfe0c3f48b472db488@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rcc35ab6be300365de5ff9587e0479d10d7d7c79070921837e3693162%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rcc35ab6be300365de5ff9587e0479d10d7d7c79070921837e3693162@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rd3f99d732baed459b425fb0a9e9e14f7843c9459b12037e4a9d753b5%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rd3f99d732baed459b425fb0a9e9e14f7843c9459b12037e4a9d753b5@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rdebc1830d6c09c11d5a4804ca26769dbd292d17d361c61dea50915f0%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rdebc1830d6c09c11d5a4804ca26769dbd292d17d361c61dea50915f0@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/re13bd219dd4b651134f6357f12bd07a0344eea7518c577bbdd185265%40%3Cissues.flink.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/re13bd219dd4b651134f6357f12bd07a0344eea7518c577bbdd185265@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/rf5230a049d989dbfdd404b4320a265dceeeba459a4d04ec21873bd55%40%3Csolr-user.lucene.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rf5230a049d989dbfdd404b4320a265dceeeba459a4d04ec21873bd55@%3Csolr-user.lucene.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLJIK2AUOZOWXR3S5XXBUNMOF3RTHTI7/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZB3GB7YXIOUKIOQ27VTIP6KKGJJ3CKL/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QLJIK2AUOZOWXR3S5XXBUNMOF3RTHTI7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WZB3GB7YXIOUKIOQ27VTIP6KKGJJ3CKL/
- https://nvd.nist.gov/vuln/detail/CVE-2019-12402
- https://security.netapp.com/advisory/ntap-20230818-0001/
- https://www.cve.org/CVERecord?id=CVE-2019-12402
- https://www.oracle.com//security-alerts/cpujul2021.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html Not ApplicableThird Party Advisory
Change history (0)
No recorded changes yet.