CVE-2019-12402 is a denial-of-service vulnerability in Apache Commons Compress versions 1.15 to 1.18, also affecting products from Fedora and Oracle. An attacker can craft archive filenames to trigger an infinite loop during file name encoding, leading to service disruption. With a CVSS score of 7.5 (High), this vulnerability is remotely exploitable with low attack complexity and no user interaction required. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.15, <= 1.18CPE matchmatch criteria | cpe:2.3:a:apache:commons_compress:*:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
>= 14.1.0, <= 14.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:banking_payments:*:*:*:*:*:*:*:* | ||
2.6.2CPE matchmatch criteria | cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.