Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 7: MGASA-2020-0001 Moderate: apache-commons-compress Resource Flaw

mageia
Calendar Grey January 5, 2020
Dist Mageia Esm H88
Security bulletin MGASA-2020-0002 addresses a critical vulnerability in the jQuery library that can result in XSS attacks.
pdated apache-commons-compress packages fix security vulnerability: A resource consumption vulnerability was discovered in apache-commons- compress in the way NioZipEncoding encod...

Summary

pdated apache-commons-compress packages fix security vulnerability:
A resource consumption vulnerability was discovered in apache-commons- compress in the way NioZipEncoding encodes filenames. Applications that use Compress to create archives, with one of the filenames within the archive being controlled by the user, may be vulnerable to this flaw. A remote attacker could exploit this flaw to cause an infinite loop during the archive creation, thus leading to a denial of service (CVE-2019-12402).

References

- https://bugs.mageia.org/show_bug.cgi?id=25365

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QLJIK2AUOZOWXR3S5XXBUNMOF3RTHTI7/

- https://www.cve.org/CVERecord?id=CVE-2019-12402

Resolution

SRPMS

- 7/core/apache-commons-compress-1.19-1.mga7

Publication date: 05 Jan 2020
URL: https://advisories.mageia.org/MGASA-2020-0001.html
Type: security
CVE: CVE-2019-12402

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here