CVE-2024-25710
Description
Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0.Users are recommended to upgrade to version 1.26.0 which fixes the issue.
Risk Information
Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.018
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2024-26308,CVE-2024-25710 are fixed in Apache-commons-compress 1.26.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0.0.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.5 | Windows |
| Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.5.20 | Windows |
| Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.1.2.16 | Windows |
| Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.2.3.9 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 11.0.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0.3.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Business Automation Workflow 22.0.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.0.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.12.0.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.1.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.2.0.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Business Automation Workflow 23.0.2 | Windows |
| Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.3.2.4 | Windows |
| Multiple Vulnerabilities are affected in IBM App Connect Enterprise 11.0.0.25 | Windows |
| Multiple Vulnerabilities are affected in IBM App Connect Enterprise 12.0.12.1 | Windows |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-4.2.0-150200.3.18.1.x86_64.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-3.9.6-150200.4.21.2.x86_64.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-api-4.2.0-150200.3.18.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) ivy-local-6.2.0-150200.3.7.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-lib-3.9.6-150200.4.21.2.x86_64.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-core-4.2.0-150200.3.18.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-mojo-4.2.0-150200.3.18.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-subst-4.2.0-150200.3.18.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-local-6.2.0-150200.3.7.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) gradle-local-6.2.0-150200.3.7.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-install-4.2.0-150200.3.18.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-minimal-4.2.0-150200.3.18.1.x86_64.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-resolve-4.2.0-150200.3.18.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-connector-4.2.0-150200.3.18.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-core-1.12.0-150200.4.7.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-jar-plugin-3.3.0-150200.3.10.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Basesystem Module 15-SP5) apache-commons-io-2.15.1-150200.3.12.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-api-1.9.18-150200.3.17.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-spi-1.9.18-150200.3.17.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-reporting-api-3.1.1-150200.3.7.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-impl-1.9.18-150200.3.17.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-util-1.9.18-150200.3.17.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Basesystem Module 15-SP5) apache-commons-codec-1.16.1-150200.3.9.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-sink-api-1.12.0-150200.4.7.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-javadoc-plugin-3.6.0-150200.4.10.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-fo-1.12.0-150200.4.7.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-sitetools-1.11.1-150200.3.7.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-apt-1.12.0-150200.4.7.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-fml-1.12.0-150200.4.7.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resources-plugin-3.3.1-150200.3.12.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) apache-commons-compress-1.26.0-150200.3.16.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-logging-api-1.12.0-150200.4.7.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-xdoc-1.12.0-150200.4.7.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-xhtml-1.12.0-150200.4.7.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-xhtml5-1.12.0-150200.4.7.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-named-locks-1.9.18-150200.3.17.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) apache-commons-configuration2-2.9.0-150200.5.5.1.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-transport-file-1.9.18-150200.3.17.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-transport-http-1.9.18-150200.3.17.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-connector-basic-1.9.18-150200.3.17.2.noarch.rpm | Linux |
| SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-transport-wagon-1.9.18-150200.3.17.2.noarch.rpm | Linux |
| apache-commons-compress Security Update (ALAS-2024-2493) apache-commons-compress-1.5-4.amzn2.0.1.noarch.rpm | Linux |
| apache-commons-compress Security Update (ALAS-2024-2493) apache-commons-compress-javadoc-1.5-4.amzn2.0.1.noarch.rpm | Linux |
| apache-commons-compress Security Update (ALAS-2024-560) apache-commons-compress-1.21-4.amzn2023.0.4.noarch.rpm | Linux |
| apache-commons-compress Security Update (ALAS-2024-560) apache-commons-compress-javadoc-1.21-4.amzn2023.0.4.noarch.rpm | Linux |
| Vulnerabilities CVE-2024-26308,CVE-2024-25710 are fixed in Apache-commons-compress for Linux 1.26.0 | Linux |
| apache-commons-compress Security Update (ALAS2023-2024-560) apache-commons-compress-1.21-4.amzn2023.0.4.noarch.rpm | Linux |
| apache-commons-compress Security Update (ALAS2023-2024-560) apache-commons-compress-javadoc-1.21-4.amzn2023.0.4.noarch.rpm | Linux |
| CVE-2024-25710 | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234