CVE-2019-12402
30.08.2019, 09:15
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
Vendor | Product | Version |
---|---|---|
apache | commons_compress | 1.15 ≤ 𝑥 ≤ 1.18 |
oracle | banking_payments | 14.1.0 ≤ 𝑥 ≤ 14.4.0 |
oracle | banking_platform | 2.6.2 |
oracle | banking_platform | 2.7.0 |
oracle | banking_platform | 2.8.0 |
oracle | banking_platform | 2.9.0 |
oracle | communications_element_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | communications_ip_service_activator | 7.3.0 |
oracle | communications_ip_service_activator | 7.4.0 |
oracle | communications_session_report_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | communications_session_route_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | customer_management_and_segmentation_foundation | 18.0 |
oracle | essbase | 21.2 |
oracle | flexcube_investor_servicing | 12.1.0 |
oracle | flexcube_investor_servicing | 12.3.0 |
oracle | flexcube_investor_servicing | 12.4.0 |
oracle | flexcube_investor_servicing | 14.0.0 |
oracle | flexcube_investor_servicing | 14.1.0 |
oracle | flexcube_private_banking | 12.0.0 |
oracle | flexcube_private_banking | 12.1.0 |
oracle | hyperion_infrastructure_technology | 11.1.2.4 |
oracle | jdeveloper | 12.2.1.4.0 |
oracle | peoplesoft_enterprise_pt_peopletools | 8.56 |
oracle | peoplesoft_enterprise_pt_peopletools | 8.57 |
oracle | peoplesoft_enterprise_pt_peopletools | 8.58 |
oracle | primavera_gateway | 18.8.0 ≤ 𝑥 ≤ 18.8.8 |
oracle | primavera_gateway | 19.12.0 |
oracle | retail_integration_bus | 15.0 |
oracle | retail_integration_bus | 16.0 |
oracle | retail_xstore_point_of_service | 15.0 |
oracle | retail_xstore_point_of_service | 16.0 |
oracle | retail_xstore_point_of_service | 17.0 |
oracle | retail_xstore_point_of_service | 18.0 |
oracle | retail_xstore_point_of_service | 19.0 |
oracle | webcenter_portal | 12.2.1.3.0 |
oracle | webcenter_portal | 12.2.1.4.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References