UBUNTU-CVE-2021-35515
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-35515
Summary:
Details: When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
References: https://ubuntu.com/security/CVE-2021-35515, https://www.openwall.com/lists/oss-security/2021/07/13/1, https://commons.apache.org/proper/commons-compress/security-reports.html, https://lists.apache.org/thread.html/r19ebfd71770ec0617a9ea180e321ef927b3fefb4c81ec5d1902d20ab%40%3Cuser.commons.apache.org%3E, http://www.openwall.com/lists/oss-security/2021/07/13/1, https://www.cve.org/CVERecord?id=CVE-2021-35515
Affected packages
Package
Name: libcommons-compress-java
Purl: pkg:deb/ubuntu/libcommons-compress-java?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
