CVE-2021-36090

Description

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress zip package.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.592

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.4.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 14.1.1.0.0Windows
Vulnerabilities CVE-2021-36090,CVE-2021-35517,CVE-2021-29842 are fixed in IBM WebSphere 21.0.0.10Windows
Vulnerabilities CVE-2021-36090,CVE-2021-35517,CVE-2021-35516,CVE-2021-35515 are fixed in Apache-commons-compress 1.21Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.57Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.58Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.59Windows
Multiple vulnerabilities are affected in Oracle Financial Services Revenue Management and Billing 2.7Windows
Multiple vulnerabilities are affected in Oracle Financial Services Revenue Management and Billing 2.8Windows
Multiple vulnerabilities are affected in Oracle Financial Services Revenue Management and Billing 2.9Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.1Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.9Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.12.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.1.0Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.2Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0Windows
SUSE-SU-2021:2612-1(SUSE Linux Enterprise Module for Development Tools 15-SP3 ) apache-commons-compress-1.21-3.3.1.noarch.rpmLinux
apache-commons-compress Security Update (ALAS-2024-2627) apache-commons-compress-javadoc-1.5-4.amzn2.0.2.noarch.rpmLinux
apache-commons-compress Security Update (ALAS-2024-2627) apache-commons-compress-1.5-4.amzn2.0.2.noarch.rpmLinux
apache-commons-compress Security Update (ALAS-2025-841) apache-commons-compress-javadoc-1.21-4.amzn2023.0.3.noarch.rpmLinux
apache-commons-compress Security Update (ALAS-2025-841) apache-commons-compress-1.21-4.amzn2023.0.3.noarch.rpmLinux
Vulnerabilities CVE-2021-36090,CVE-2021-35517,CVE-2021-35516,CVE-2021-35515 are fixed in Apache-commons-compress for Linux 1.21Linux
apache-commons-compress Security Update (ALAS2-2024-2627) apache-commons-compress-1.5-4.amzn2.0.2.noarch.rpmLinux
apache-commons-compress Security Update (ALAS2-2024-2627) apache-commons-compress-javadoc-1.5-4.amzn2.0.2.noarch.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234