CVE-2021-35517
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2021-35517. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
Available Exploits
Related News
Affected Products
Affected Versions:
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Improper Handling of Length Parameter Inconsistency in Compress
GHSA-xqfj-vm6h-2x34Advisory Details
Affected Packages
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Advisory provided by GitHub Security Advisory Database. Published: August 2, 2021, Modified: February 8, 2022