CVE-2021-35515

Description

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress sevenz package.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.598

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-36090,CVE-2021-35517,CVE-2021-35516,CVE-2021-35515 are fixed in Apache-commons-compress 1.21Windows
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Insight 2.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.1Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.12.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.1.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0Windows
SUSE-SU-2021:2612-1(SUSE Linux Enterprise Module for Development Tools 15-SP3 ) apache-commons-compress-1.21-3.3.1.noarch.rpmLinux
Vulnerabilities CVE-2021-36090,CVE-2021-35517,CVE-2021-35516,CVE-2021-35515 are fixed in Apache-commons-compress for Linux 1.21Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234