Описание
Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.1 (исключая)
cpe:2.3:a:junrar_project:junrar:*:*:*:*:*:*:*:*
EPSS
Процентиль: 61%
0.00414
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-835
Связанные уязвимости
CVSS3: 3.3
redhat
больше 7 лет назад
Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.
EPSS
Процентиль: 61%
0.00414
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-835