Apache Commons Compress Multiple Denial of Service Vulnerabilities (CVE-2018-1324)
Apache Commons Compress Multiple Denial of Service Vulnerabilities (CVE-2018-1324)
Release date:
Updated on:
Affected Systems:
Apache Group Commons Compress 1.11-1.15
Description:
Bugtraq id: 103490
CVE (CAN) ID: CVE-2018-1324
The Apache Commons Compress library defines an API that can process ar, cpio, Unix dump, tar, zip, gzip, XZ, Pack200, and bzip2 files.
In Apache Commons Compress 1.11-1.15, The ZipFile and ZipArchiveInputStream classes use an extra field parser to create an infinite loop when processing constructed ZIP files, this allows attackers to launch denial-of-service attacks against affected services.
<* Source: Luis Filipe Nassif
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apache.org/
Https://lists.apache.org/thread.html/1c7b6df6d1c5c8583518a0afa017782924918e4d6acfaf23ed5b2089@%3Cdev.commons.apache.org%3E
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151579.htm