CVE-2012-2098
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 12.61% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- apache/commons compress
- Source
- secalert@redhat.com
References
- http://ant.apache.org/security.htmlVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0130.htmlThird Party Advisory
- http://commons.apache.org/compress/security.htmlVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081697.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081746.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105049.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105060.htmlThird Party Advisory
- http://osvdb.org/82161Broken Link
- http://packetstormsecurity.org/files/113014/Apache-Commons-Compress-Apache-Ant-Denial-Of-Service.htmlThird Party Advisory
- http://secunia.com/advisories/49255Vendor Advisory
- http://secunia.com/advisories/49286Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21644047Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/09/13/3
- http://www.securityfocus.com/bid/53676Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1027096Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75857Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
- http://ant.apache.org/security.htmlVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0130.htmlThird Party Advisory
- http://commons.apache.org/compress/security.htmlVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081697.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081746.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105049.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105060.htmlThird Party Advisory
- http://osvdb.org/82161Broken Link
- http://packetstormsecurity.org/files/113014/Apache-Commons-Compress-Apache-Ant-Denial-Of-Service.htmlThird Party Advisory
- http://secunia.com/advisories/49255Vendor Advisory
- http://secunia.com/advisories/49286Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21644047Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.