apache-commons-compress: ZipArchiveInputStream.read() fails to identify correct EOF allowing for DoS via crafted zip
Published Aug 16, 2018
5.5
MEDIUMCVSS 3.1
EPSS 5.25%
Description
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service attack against services that use Compress' zip package.
Affected products
-
- Version 1.7 to 1.17StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Commons Compress | n/a |
|
Configuration 1
- ≥ 1.7.0 · ≤ 1.17.0
Configuration 2
- 14.1.1.0.0
No data.
Red Hat Fuse 7.6.0
commons-compress
Fixed · RHSA-2020:0983
JBoss Developer Studio 11
commons-compress
Out of support scope
Red Hat BPM Suite 6
commons-compress
Out of support scope
Red Hat Enterprise Linux 7
apache-commons-compress
Not affected
Red Hat Enterprise Linux 8
apache-commons-compress
Not affected
Red Hat JBoss BRMS 6
commons-compress
Out of support scope
Red Hat JBoss Data Virtualization 6
commons-compress
Out of support scope
Red Hat JBoss Fuse 6
commons-compress
Out of support scope
Red Hat JBoss Fuse Service Works 6
commons-compress
Out of support scope
Red Hat JBoss Operations Network 3
commons-compress
Out of support scope
Red Hat Mobile Application Platform 4
commons-compress
Out of support scope
Red Hat OpenStack Platform 8 (Liberty)
opendaylight
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Will not fix
Red Hat Satellite 6
lucene4-contrib
Out of support scope
Red Hat Software Collections
rh-java-common-apache-commons-compress
Not affected
Red Hat Software Collections
rh-maven35-apache-commons-compress
Will not fix
Red Hat Storage 3
commons-compress
Will not fix
Red Hat Virtualization 4
apache-commons-compress
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.6.0 | commons-compress | Fixed | RHSA-2020:0983 |
| JBoss Developer Studio 11 | commons-compress | Out of support scope | n/a |
| Red Hat BPM Suite 6 | commons-compress | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | apache-commons-compress | Not affected | n/a |
| Red Hat Enterprise Linux 8 | apache-commons-compress | Not affected | n/a |
| Red Hat JBoss BRMS 6 | commons-compress | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | commons-compress | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | commons-compress | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | commons-compress | Out of support scope | n/a |
| Red Hat JBoss Operations Network 3 | commons-compress | Out of support scope | n/a |
| Red Hat Mobile Application Platform 4 | commons-compress | Out of support scope | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Will not fix | n/a |
| Red Hat Satellite 6 | lucene4-contrib | Out of support scope | n/a |
| Red Hat Software Collections | rh-java-common-apache-commons-compress | Not affected | n/a |
| Red Hat Software Collections | rh-maven35-apache-commons-compress | Will not fix | n/a |
| Red Hat Storage 3 | commons-compress | Will not fix | n/a |
| Red Hat Virtualization 4 | apache-commons-compress | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (36)
- http://www.securityfocus.com/bid/105139 vdb-entryx_refsource_BIDBroken Link
- http://www.securitytracker.com/id/1041503 vdb-entryx_refsource_SECTRACKBroken Link
- https://access.redhat.com/security/cve/CVE-2018-11771 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618573 Issue Tracking
- https://github.com/advisories/GHSA-hrmr-f5m6-m9pq Advisory
- https://lists.apache.org/thread.html/0adb631517766e793e18a59723e2df08ced41eb9a57478f14781c9f7%40%3Cdev.tinkerpop.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/0adb631517766e793e18a59723e2df08ced41eb9a57478f14781c9f7@%3Cdev.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/3565494c263dfeb4dcb2a71cb24d09a1ca285cd6ac74edc025a3af8a%40%3Ccommits.tinkerpop.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/3565494c263dfeb4dcb2a71cb24d09a1ca285cd6ac74edc025a3af8a@%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/35f60d6d0407c13c39411038ba1aca71d92595ed7041beff4d07f2ee%40%3Ccommits.tinkerpop.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/35f60d6d0407c13c39411038ba1aca71d92595ed7041beff4d07f2ee@%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/6c79965066c30d4e330e04d911d3761db41b82c89ae38d9a6b37a6f1%40%3Cdev.tinkerpop.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/6c79965066c30d4e330e04d911d3761db41b82c89ae38d9a6b37a6f1@%3Cdev.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/714c6ac1b1b50f8557e7342903ef45f1538a7bc60a0b47d6e48c273d%40%3Ccommits.tinkerpop.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/714c6ac1b1b50f8557e7342903ef45f1538a7bc60a0b47d6e48c273d@%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/b8da751fc0ca949534cdf2744111da6bb0349d2798fac94b0a50f330%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/b8da751fc0ca949534cdf2744111da6bb0349d2798fac94b0a50f330@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/b8ef29df0f1d55aa741170748352ae8e425c7b1d286b2f257711a2dd%40%3Cdev.creadur.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/b8ef29df0f1d55aa741170748352ae8e425c7b1d286b2f257711a2dd@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/b907e70bc422905d7962fd18f863f746bf7b4e7ed9da25c148580c61%40%3Cnotifications.commons.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/b907e70bc422905d7962fd18f863f746bf7b4e7ed9da25c148580c61@%3Cnotifications.commons.apache.org%3E
- https://lists.apache.org/thread.html/c7954dc1e8fafd7ca1449f078953b419ebf8936e087f235f3bd024be%40%3Ccommits.tinkerpop.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/c7954dc1e8fafd7ca1449f078953b419ebf8936e087f235f3bd024be@%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/e3eae9e6fc021c4c22dda59a335d21c12eecab480b48115a2f098ef6%40%3Ccommits.tinkerpop.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/e3eae9e6fc021c4c22dda59a335d21c12eecab480b48115a2f098ef6@%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/eeecc1669242b28a3777ae13c68b376b0148d589d3d8170340d61120%40%3Cdev.tinkerpop.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/eeecc1669242b28a3777ae13c68b376b0148d589d3d8170340d61120@%3Cdev.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/f28052d04cb8dbaae39bfd3dc8438e58c2a8be306a3f381f4728d7c1%40%3Ccommits.commons.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f28052d04cb8dbaae39bfd3dc8438e58c2a8be306a3f381f4728d7c1@%3Ccommits.commons.apache.org%3E
- https://lists.apache.org/thread.html/f9cdd32af7d73e943452167d15801db39e8130409ebb9efb243b3f41%40%3Ccommits.tinkerpop.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f9cdd32af7d73e943452167d15801db39e8130409ebb9efb243b3f41@%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2018-11771
- https://www.cve.org/CVERecord?id=CVE-2018-11771
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.