CVE-2021-35517
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
Published:Jul 13, 2021
Last Modified:Nov 21, 2024
EPS:Jul 13, 2021
EPSS Score:0.00313
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Commons Compress
Apache
Commons Compress
Vendor
Netapp
Product
Active Iq Unified Manager
Netapp
Active Iq Unified Manager
Vendor
Netapp
Product
Oncommand Insight
Netapp
Oncommand Insight
Vendor
Oracle
Product
Banking Apis
Oracle
Banking Apis
Vendor
Oracle
Product
Banking Digital Experience
Oracle
Banking Digital Experience
Vendor
Oracle
Product
Banking Enterprise Default Management
Oracle
Banking Enterprise Default Management
Vendor
Oracle
Product
Banking Party Management
Oracle
Banking Party Management
Vendor
Oracle
Product
Banking Payments
Oracle
Banking Payments
Vendor
Oracle
Product
Banking Trade Finance
Oracle
Banking Trade Finance
Vendor
Oracle
Product
Banking Treasury Management
Oracle
Banking Treasury Management
Vendor
Oracle
Product
Business Process Management Suite
Oracle
Business Process Management Suite
Vendor
Oracle
Product
Commerce Guided Search
Oracle
Commerce Guided Search
Vendor
Oracle
Product
Communications Billing And Revenue Management
Oracle
Communications Billing And Revenue Management
Vendor
Oracle
Product
Communications Cloud Native Core Service Communication Proxy
Oracle
Communications Cloud Native Core Service Communication Proxy
Vendor
Oracle
Product
Communications Cloud Native Core Unified Data Repository
Oracle
Communications Cloud Native Core Unified Data Repository
Vendor
Oracle
Product
Communications Diameter Intelligence Hub
Oracle
Communications Diameter Intelligence Hub
Vendor
Oracle
Product
Communications Messaging Server
Oracle
Communications Messaging Server
Vendor
Oracle
Product
Communications Session Route Manager
Oracle
Communications Session Route Manager
Vendor
Oracle
Product
Financial Services Crime And Compliance Management Studio
Oracle
Financial Services Crime And Compliance Management Studio
Vendor
Oracle
Product
Financial Services Enterprise Case Management
Oracle
Financial Services Enterprise Case Management
Vendor
Oracle
Product
Flexcube Universal Banking
Oracle
Flexcube Universal Banking
Vendor
Oracle
Product
Healthcare Data Repository
Oracle
Healthcare Data Repository
Vendor
Oracle
Product
Insurance Policy Administration
Oracle
Insurance Policy Administration
Vendor
Oracle
Product
Peoplesoft Enterprise Peopletools
Oracle
Peoplesoft Enterprise Peopletools
Vendor
Oracle
Product
Primavera Unifier
Oracle
Primavera Unifier
Vendor
Oracle
Product
Utilities Testing Accelerator
Oracle
Utilities Testing Accelerator
Vendor
Oracle
Product
Webcenter Portal
Oracle
Webcenter Portal
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Vendor
Redhat
Product
Rhev Manager
Redhat
Rhev Manager
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
