Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-25710

Опубликовано: 19 фев. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue.

A loop with an unreachable exit condition (Infinite Loop) vulnerability was found in Apache Common Compress. This issue can lead to a denial of service.

Меры по смягчению последствий

No mitigation is currently available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
AMQ Clientscommons-compressNot affected
A-MQ Clients 2commons-compressNot affected
Cryostat 2commons-compressNot affected
Logging Subsystem for Red Hat OpenShiftorg.elasticsearch-elasticsearchNot affected
Red Hat Ansible Automation Platform 2commons-compressWill not fix
Red Hat build of Apache Camel for Spring Boot 3commons-compressNot affected
Red Hat build of Apache Camel for Spring Boot 4commons-compressAffected
Red Hat build of Debezium 2commons-compressNot affected
Red Hat Build of Keycloakcommons-compressNot affected
Red Hat build of OptaPlanner 8commons-compressWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2264988commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file

EPSS

Процентиль: 4%
0.00018
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 2 года назад

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue.

CVSS3: 8.1
nvd
почти 2 года назад

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue.

CVSS3: 5.5
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 8.1
debian
почти 2 года назад

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...

CVSS3: 5.9
github
почти 2 года назад

Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file

EPSS

Процентиль: 4%
0.00018
Низкий

5.5 Medium

CVSS3