CVE-2018-1324
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2018-1324. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
Available Exploits
Related News
Affected Products
Affected Versions:
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Apache Commons Compress vulnerable to denial of service due to infinite loop
GHSA-h436-432x-8fvxAdvisory Details
Affected Packages
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References
Advisory provided by GitHub Security Advisory Database. Published: March 14, 2019, Modified: February 27, 2024