{"id":"CVE-2012-2098","aliases":["GHSA-6fxm-66hq-fc96"],"url":"https://o3.security/vulnerability/CVE-2012-2098","summary":"Uncontrolled Resource Consumption in Apache Commons Compress","details":"Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.","published":"2012-06-29T19:55:03Z","modified":"2026-04-16T06:26:24.215404907Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.commons:commons-compress","fixedVersion":"1.4.1"}],"fix":{"url":"https://github.com/apache/commons-compress/commit/020c03d8ef579e80511023fb46ece30e9c3dd27d","label":"apache/commons-compress@020c03d"},"references":[{"type":"ADVISORY","url":"http://ant.apache.org/security.html"},{"type":"ADVISORY","url":"http://archives.neohapsis.com/archives/bugtraq/2012-05/0130.html"},{"type":"ADVISORY","url":"http://commons.apache.org/compress/security.html"},{"type":"ADVISORY","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081697.html"},{"type":"ADVISORY","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081746.html"},{"type":"ADVISORY","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105049.html"},{"type":"ADVISORY","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105060.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.org/files/113014/Apache-Commons-Compress-Apache-Ant-Denial-Of-Service.html"},{"type":"ADVISORY","url":"http://secunia.com/advisories/49255"},{"type":"ADVISORY","url":"http://secunia.com/advisories/49286"},{"type":"ADVISORY","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21644047"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/53676"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id?1027096"},{"type":"ADVISORY","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/75857"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"WEB","url":"http://osvdb.org/82161"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/13/3"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2098"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/020c03d8ef579e80511023fb46ece30e9c3dd27d"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/0600296ab8f8a0bbdfedd483f51b38005eb8e34e"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/1ce57d976c4f25fe99edcadf079840c278f3cb84"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/2ab2fcb356753927afaa731b9d2dcc47d3083408"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/654222e628097763ee6ca561ae77be5c06666173"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/6ced422bf5eca3aac05396367bafb33ec21bf74e"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/6e95697e783767f3549f00d7d2e1b002eac4a3d4"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/8f702469cbf4c451b6dea349290bc4af0f6f76c7"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/b06f7b41c936ef1a79589d16ea5c1d8b93f71f66"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/cca0e6e5341aacddefd4c4d36cef7cbdbc2a8777"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/ea31005111f0abede7e43e4ba0012e62e0808b22"},{"type":"WEB","url":"https://github.com/apache/commons-compress/commit/fdd7459bc5470e90024dbe762249166481cce769"},{"type":"WEB","url":"https://web.archive.org/web/20140724002926/http://secunia.com/advisories/49286"},{"type":"WEB","url":"https://web.archive.org/web/20140724023114/http://secunia.com/advisories/49255"},{"type":"WEB","url":"https://web.archive.org/web/20200517014414/http://www.securitytracker.com/id?1027096"},{"type":"WEB","url":"https://web.archive.org/web/20130525085523/http://www.securityfocus.com/bid/53676"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@<solr-user.lucene.apache.org>"},{"type":"PACKAGE","url":"https://github.com/apache/commons-compress"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-16T06:26:24.215404907Z"}}