Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Commons_compress | Apache | * | 1.4.1 (excluding) |
| Libcommons-compress-java | Ubuntu | lucid | * |
| Libcommons-compress-java | Ubuntu | natty | * |
| Libcommons-compress-java | Ubuntu | oneiric | * |
| Libcommons-compress-java | Ubuntu | precise | * |
| Libcommons-compress-java | Ubuntu | upstream | * |