Описание
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
Отчет
This issue affects the versions of lucene4 as shipped with Red Hat Enterprise Satellite 6.0 and 6.1. Red Hat Satellite 6.2 and later do not include the lucene4 component and are not affected.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| JBoss Developer Studio 11 | commons-compress | Not affected | ||
| Red Hat BPM Suite 6 | commons-compress | Not affected | ||
| Red Hat Enterprise Linux 7 | apache-commons-compress | Not affected | ||
| Red Hat Enterprise Linux 8 | apache-commons-compress | Not affected | ||
| Red Hat JBoss BRMS 5 | commons-compress | Not affected | ||
| Red Hat JBoss BRMS 6 | commons-compress | Not affected | ||
| Red Hat JBoss Data Virtualization 6 | commons-compress | Will not fix | ||
| Red Hat JBoss Fuse 6 | commons-compress | Not affected | ||
| Red Hat JBoss Fuse Service Works 6 | commons-compress | Not affected | ||
| Red Hat Mobile Application Platform 4 | commons-compress | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
A specially crafted ZIP archive can be used to cause an infinite loop ...
Apache Commons Compress vulnerable to denial of service due to infinite loop
Уязвимость реализации классов ZipFile и ZipArchiveInputStream набора инструментов для сжатия Commons Compress, связанная с бесконечной работой цикла, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3