CVE-2024-25710

Description

Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0.Users are recommended to upgrade to version 1.26.0 which fixes the issue.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.018

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2024-26308,CVE-2024-25710 are fixed in Apache-commons-compress 1.26.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0.0.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.5Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.5.20Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.1.2.16Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.2.3.9Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 11.0.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0.3Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0.3.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 22.0.2Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.12.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.1.0Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.2.0.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 23.0.2Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.3.2.4Windows
Multiple Vulnerabilities are affected in IBM App Connect Enterprise 11.0.0.25Windows
Multiple Vulnerabilities are affected in IBM App Connect Enterprise 12.0.12.1Windows
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-4.2.0-150200.3.18.1.x86_64.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-3.9.6-150200.4.21.2.x86_64.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-api-4.2.0-150200.3.18.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) ivy-local-6.2.0-150200.3.7.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-lib-3.9.6-150200.4.21.2.x86_64.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-core-4.2.0-150200.3.18.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-mojo-4.2.0-150200.3.18.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-subst-4.2.0-150200.3.18.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-local-6.2.0-150200.3.7.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) gradle-local-6.2.0-150200.3.7.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-install-4.2.0-150200.3.18.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-minimal-4.2.0-150200.3.18.1.x86_64.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-resolve-4.2.0-150200.3.18.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) xmvn-connector-4.2.0-150200.3.18.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-core-1.12.0-150200.4.7.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-jar-plugin-3.3.0-150200.3.10.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Basesystem Module 15-SP5) apache-commons-io-2.15.1-150200.3.12.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-api-1.9.18-150200.3.17.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-spi-1.9.18-150200.3.17.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-reporting-api-3.1.1-150200.3.7.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-impl-1.9.18-150200.3.17.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-util-1.9.18-150200.3.17.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Basesystem Module 15-SP5) apache-commons-codec-1.16.1-150200.3.9.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-sink-api-1.12.0-150200.4.7.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-javadoc-plugin-3.6.0-150200.4.10.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-fo-1.12.0-150200.4.7.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-sitetools-1.11.1-150200.3.7.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-apt-1.12.0-150200.4.7.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-fml-1.12.0-150200.4.7.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resources-plugin-3.3.1-150200.3.12.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) apache-commons-compress-1.26.0-150200.3.16.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-logging-api-1.12.0-150200.4.7.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-xdoc-1.12.0-150200.4.7.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-xhtml-1.12.0-150200.4.7.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-doxia-module-xhtml5-1.12.0-150200.4.7.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-named-locks-1.9.18-150200.3.17.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) apache-commons-configuration2-2.9.0-150200.5.5.1.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-transport-file-1.9.18-150200.3.17.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-transport-http-1.9.18-150200.3.17.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-connector-basic-1.9.18-150200.3.17.2.noarch.rpmLinux
SUSE-SU-2024:0726-1(Development Tools Module 15-SP5) maven-resolver-transport-wagon-1.9.18-150200.3.17.2.noarch.rpmLinux
apache-commons-compress Security Update (ALAS-2024-2493) apache-commons-compress-1.5-4.amzn2.0.1.noarch.rpmLinux
apache-commons-compress Security Update (ALAS-2024-2493) apache-commons-compress-javadoc-1.5-4.amzn2.0.1.noarch.rpmLinux
apache-commons-compress Security Update (ALAS-2024-560) apache-commons-compress-1.21-4.amzn2023.0.4.noarch.rpmLinux
apache-commons-compress Security Update (ALAS-2024-560) apache-commons-compress-javadoc-1.21-4.amzn2023.0.4.noarch.rpmLinux
Vulnerabilities CVE-2024-26308,CVE-2024-25710 are fixed in Apache-commons-compress for Linux 1.26.0Linux
apache-commons-compress Security Update (ALAS2023-2024-560) apache-commons-compress-1.21-4.amzn2023.0.4.noarch.rpmLinux
apache-commons-compress Security Update (ALAS2023-2024-560) apache-commons-compress-javadoc-1.21-4.amzn2023.0.4.noarch.rpmLinux
CVE-2024-25710NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234