Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21389
HistoryAug 28, 2019 - 4:19 a.m.

Denial Of Service (Dos)

2019-08-2804:19:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

0.005 Low

EPSS

Percentile

76.3%

commons-compress is vulnerable to denial of service. The file name encoding algorithm can result in an infinite loop when faced with malicious input. This allows an attacker to cause a denial of service condition using the file names inside of an archive created by Compress.

References