Back

HIGH

apache-commons-compress: Infinite loop in name encoding algorithm

Published Aug 29, 2019

Description

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

Affected products

Remediation

Red Hat statement

This issue does not affect the versions of apache-commons-compress as shipped with Red Hat Enterprise Linux 7, and the versions of rh-java-common-apache-commons-compress and rh-maven35-apache-commons-compress as shipped with Red Hat Software Collections 3, as they used a fallback zip encoding implementation (leveraging java.io) to encode filenames. This issue does not affect the versions of rh-maven36-apache-commons-compress as shipped with Red Hat Software Collection 3 as they already include the patch.

Weaknesses (1)

References (58)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Aug 29, 2019
Updated Aug 4, 2024
Reserved May 28, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 27, 2019
ENISA EUVD
Assigner apache
Published Aug 29, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-0685 GHSA-53X6-4X5P-RRVV