SUSE-SU-2021:2612-1
Dashboard / Vulnerabilities / SUSE-SU-2021:2612-1
SUSE-SU-2021:2612-1
Summary: Security update for apache-commons-compress
Details: This update for apache-commons-compress fixes the following issues: - Updated to 1.21 - CVE-2021-35515: Fixed an infinite loop when reading a specially crafted 7Z archive. (bsc#1188463) - CVE-2021-35516: Fixed an excessive memory allocation when reading a specially crafted 7Z archive. (bsc#1188464) - CVE-2021-35517: Fixed an excessive memory allocation when reading a specially crafted TAR archive. (bsc#1188465) - CVE-2021-36090: Fixed an excessive memory allocation when reading a specially crafted ZIP archive. (bsc#1188466)
References: https://www.suse.com/support/update/announcement/2021/suse-su-20212612-1/, https://bugzilla.suse.com/1188463, https://bugzilla.suse.com/1188464, https://bugzilla.suse.com/1188465, https://bugzilla.suse.com/1188466, https://www.suse.com/security/cve/CVE-2021-35515, https://www.suse.com/security/cve/CVE-2021-35516, https://www.suse.com/security/cve/CVE-2021-35517, https://www.suse.com/security/cve/CVE-2021-36090
Affected packages
Package
Name: apache-commons-compress
Purl: pkg:rpm/suse/apache-commons-compress&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
