PT-2021-3726 · Apache+4 · Apache Commons Compress+4

Oss Fuzz

·

Published

2021-07-13

·

Updated

2024-08-06

·

CVE-2021-36090

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Commons Compress versions 1.19 through 1.21 Confluence Data Center versions from 7.19.23 to 8.9.3 Confluence Data Center versions from 8.5.10 to 8.5.11 Confluence Server versions from 7.19.23 to 7.19.24 Confluence Server versions from 8.5.10 to 8.5.11
Description The issue is related to errors in handling input data length parameters, which can lead to a denial of service attack. When reading a specially crafted ZIP archive, Compress can allocate large amounts of memory, resulting in an out of memory error even for small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
Recommendations For Confluence Data Center versions from 8.9.2 to 8.9.3, upgrade to version 8.9.4. For Confluence Data Center versions from 8.5.10 to 8.5.11 LTS, upgrade to version 8.9.4 or 8.5.12 LTS. For Confluence Data Center versions from 7.19.23 to 7.19.24 LTS, upgrade to version 8.9.4 or 8.5.12 LTS or 7.19.25 LTS. For Confluence Server versions from 8.5.10 to 8.5.11 LTS, upgrade to version 8.5.12 LTS. For Confluence Server versions from 7.19.23 to 7.19.24 LTS, upgrade to version 8.5.12 LTS or 7.19.25 LTS. As a temporary workaround, consider restricting the use of the zip package in Compress to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-45411
BDU:2021-03966
CVE-2021-36090
GHSA-MC84-PJ99-Q6HH
MGASA-2022-0009
OESA-2021-1302
OPENSUSE-SU-2021:1115-1
OPENSUSE-SU-2021:2612-1
OPENSUSE-SU-2021_1115-1
OPENSUSE-SU-2021_2612-1
OPENSUSE-SU-2024:10618-1
RHSA-2022:5555
SUSE-SU-2021:2612-1

Affected Products

Apache Commons Compress
Confluence
Debian
Red Os
Suse