openSUSE-SU-2021:2612-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:2612-1
openSUSE-SU-2021:2612-1
Summary: Security update for apache-commons-compress
Details: This update for apache-commons-compress fixes the following issues: - Updated to 1.21 - CVE-2021-35515: Fixed an infinite loop when reading a specially crafted 7Z archive. (bsc#1188463) - CVE-2021-35516: Fixed an excessive memory allocation when reading a specially crafted 7Z archive. (bsc#1188464) - CVE-2021-35517: Fixed an excessive memory allocation when reading a specially crafted TAR archive. (bsc#1188465) - CVE-2021-36090: Fixed an excessive memory allocation when reading a specially crafted ZIP archive. (bsc#1188466)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/XVOH7P2WI6SSS2OORQJBS45T5SKKO7BV/, https://bugzilla.suse.com/1188463, https://bugzilla.suse.com/1188464, https://bugzilla.suse.com/1188465, https://bugzilla.suse.com/1188466, https://www.suse.com/security/cve/CVE-2021-35515, https://www.suse.com/security/cve/CVE-2021-35516, https://www.suse.com/security/cve/CVE-2021-35517, https://www.suse.com/security/cve/CVE-2021-36090
Affected packages
Package
Name: apache-commons-compress
Purl: pkg:rpm/opensuse/apache-commons-compress&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
