Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xqr-grq4-qwgx

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Junrar vulnerable to Infinite Loop

Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.

Пакеты

Наименование

com.github.junrar:junrar

maven
Затронутые версииВерсия исправления

< 1.0.1

1.0.1

EPSS

Процентиль: 61%
0.00414
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 3.3
redhat
больше 7 лет назад

Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.

CVSS3: 5.5
nvd
больше 7 лет назад

Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.

EPSS

Процентиль: 61%
0.00414
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-835