Vulnerability

CVE-2012-2098
CVSS Score 5.0 medium

CVSS Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

CWE

CWE-310

[CVE-2012-2098] CWE-310

Description

Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.

See org.codehaus.plexus/plexus-archiver package information