[java-sig-commits] [Bug 824708] New: CVE-2012-2098 apache-commons-compress: denial of service flaw when compressing certain files [fedora-all]

bugzilla at redhat.com bugzilla at redhat.com
Thu May 24 03:33:26 UTC 2012


https://bugzilla.redhat.com/show_bug.cgi?id=824708

            Bug ID: 824708
          Keywords: Security, SecurityTracking
            Blocks: 810406
        QA Contact: extras-qa at fedoraproject.org
          Severity: low
           Version: 16
          Priority: low
                CC: java-sig-commits at lists.fedoraproject.org,
                    sm at sandro-mathys.ch, SpikeFedora at gmail.com
          Assignee: sm at sandro-mathys.ch
           Summary: CVE-2012-2098 apache-commons-compress: denial of
                    service flaw when compressing certain files
                    [fedora-all]
        Regression: ---
      Story Points: ---
    Classification: Fedora
                OS: Linux
          Reporter: djorm at redhat.com
              Type: ---
     Documentation: ---
          Hardware: All
        Mount Type: ---
            Status: NEW
         Component: apache-commons-compress
           Product: Fedora


This is an automatically created tracking bug!  It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.

For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.

For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs

When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs).  Please mention the CVE IDs being fixed
in the RPM changelog when available.

Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=810406

Please note: this issue affects multiple supported versions of Fedora.
Only one tracking bug has been filed; please ensure that it is only closed
when all affected versions are fixed.


[bug automatically created by: add-tracking-bugs]

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the java-sig-commits mailing list