Denial of Service in Apache Commons Compress
High severity
GitHub Reviewed
Published
Oct 11, 2019
to the GitHub Advisory Database
•
Updated Oct 9, 2023
Description
Published by the National Vulnerability Database
Aug 30, 2019
Reviewed
Sep 30, 2019
Published to the GitHub Advisory Database
Oct 11, 2019
Last updated
Oct 9, 2023
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
References