CVE-2021-35516

Description

When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress sevenz package.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.402

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-36090,CVE-2021-35517,CVE-2021-35516,CVE-2021-35515 are fixed in Apache-commons-compress 1.21Windows
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Insight 2.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.1Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.12.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.1.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0Windows
SUSE-SU-2021:2612-1(SUSE Linux Enterprise Module for Development Tools 15-SP3 ) apache-commons-compress-1.21-3.3.1.noarch.rpmLinux
Vulnerabilities CVE-2021-36090,CVE-2021-35517,CVE-2021-35516,CVE-2021-35515 are fixed in Apache-commons-compress for Linux 1.21Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234