Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:2612-1

Опубликовано: 05 авг. 2021
Источник: suse-cvrf

Описание

Security update for apache-commons-compress

This update for apache-commons-compress fixes the following issues:

  • Updated to 1.21
  • CVE-2021-35515: Fixed an infinite loop when reading a specially crafted 7Z archive. (bsc#1188463)
  • CVE-2021-35516: Fixed an excessive memory allocation when reading a specially crafted 7Z archive. (bsc#1188464)
  • CVE-2021-35517: Fixed an excessive memory allocation when reading a specially crafted TAR archive. (bsc#1188465)
  • CVE-2021-36090: Fixed an excessive memory allocation when reading a specially crafted ZIP archive. (bsc#1188466)

Список пакетов

Container containers/apache-pulsar:3.3
apache-commons-compress-1.21-3.3.1
Container suse/manager/5.0/x86_64/server:latest
apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3
apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
apache-commons-compress-1.21-3.3.1
Image server-image
apache-commons-compress-1.21-3.3.1
SUSE Linux Enterprise Module for Development Tools 15 SP2
apache-commons-compress-1.21-3.3.1
SUSE Linux Enterprise Module for Development Tools 15 SP3
apache-commons-compress-1.21-3.3.1

Описание

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.


Затронутые продукты
Container containers/apache-pulsar:3.3:apache-commons-compress-1.21-3.3.1
Container suse/manager/5.0/x86_64/server:latest:apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc:apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:apache-commons-compress-1.21-3.3.1

Ссылки

Описание

When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.


Затронутые продукты
Container containers/apache-pulsar:3.3:apache-commons-compress-1.21-3.3.1
Container suse/manager/5.0/x86_64/server:latest:apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc:apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:apache-commons-compress-1.21-3.3.1

Ссылки

Описание

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.


Затронутые продукты
Container containers/apache-pulsar:3.3:apache-commons-compress-1.21-3.3.1
Container suse/manager/5.0/x86_64/server:latest:apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc:apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:apache-commons-compress-1.21-3.3.1

Ссылки

Описание

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.


Затронутые продукты
Container containers/apache-pulsar:3.3:apache-commons-compress-1.21-3.3.1
Container suse/manager/5.0/x86_64/server:latest:apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc:apache-commons-compress-1.21-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:apache-commons-compress-1.21-3.3.1

Ссылки
Уязвимость SUSE-SU-2021:2612-1