CVE Vulnerabilities

CVE-2012-2098

Published: Jun 29, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.

Affected Software

NameVendorStart VersionEnd Version
Commons_compressApache*1.4.1 (excluding)
Libcommons-compress-javaUbuntulucid*
Libcommons-compress-javaUbuntunatty*
Libcommons-compress-javaUbuntuoneiric*
Libcommons-compress-javaUbuntuprecise*
Libcommons-compress-javaUbuntuupstream*

References