Описание
Security update for apache-commons-compress
This update for apache-commons-compress fixes the following issues:
- Updated to 1.21
- CVE-2021-35515: Fixed an infinite loop when reading a specially crafted 7Z archive. (bsc#1188463)
- CVE-2021-35516: Fixed an excessive memory allocation when reading a specially crafted 7Z archive. (bsc#1188464)
- CVE-2021-35517: Fixed an excessive memory allocation when reading a specially crafted TAR archive. (bsc#1188465)
- CVE-2021-36090: Fixed an excessive memory allocation when reading a specially crafted ZIP archive. (bsc#1188466)
Список пакетов
Container containers/apache-pulsar:3.3
Container suse/manager/5.0/x86_64/server:latest
Image SLES15-SP4-Manager-Server-4-3
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
Image SLES15-SP4-Manager-Server-4-3-BYOS
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
Image server-image
SUSE Linux Enterprise Module for Development Tools 15 SP2
SUSE Linux Enterprise Module for Development Tools 15 SP3
Ссылки
- Link for SUSE-SU-2021:2612-1
- E-Mail link for SUSE-SU-2021:2612-1
- SUSE Security Ratings
- SUSE Bug 1188463
- SUSE Bug 1188464
- SUSE Bug 1188465
- SUSE Bug 1188466
- SUSE CVE CVE-2021-35515 page
- SUSE CVE CVE-2021-35516 page
- SUSE CVE CVE-2021-35517 page
- SUSE CVE CVE-2021-36090 page
Описание
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
Затронутые продукты
Ссылки
- CVE-2021-35515
- SUSE Bug 1188463
Описание
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
Затронутые продукты
Ссылки
- CVE-2021-35516
- SUSE Bug 1188464
Описание
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
Затронутые продукты
Ссылки
- CVE-2021-35517
- SUSE Bug 1188465
- SUSE Bug 1188468
Описание
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
Затронутые продукты
Ссылки
- CVE-2021-36090
- SUSE Bug 1188466
- SUSE Bug 1188469