This repository was archived by the owner on Oct 27, 2020. It is now read-only.
CVE-2018-11771 Medium Severity Vulnerability detected by WhiteSource #207
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2018-11771 - Medium Severity Vulnerability
Apache Commons Compress software defines an API for working with compression and archive formats. These include: bzip2, gzip, pack200, lzma, xz, Snappy, traditional Unix Compress, DEFLATE, LZ4, Brotli and ar, cpio, jar, tar, zip, dump, 7z, arj.
Library home page: http://commons.apache.org/proper/commons-compress/
Path to dependency file: /alfresco-remote-api/pom.xml
Path to vulnerable library: /root/.m2/repository/org/apache/commons/commons-compress/1.15/commons-compress-1.15.jar
Dependency Hierarchy:
Found in HEAD commit: 0da7eda5156750f521e172741ac40cdbb40cdfa5
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service attack against services that use Compress' zip package.
Publish Date: 2018-08-16
URL: CVE-2018-11771
Base Score Metrics:
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2018-11771
Release Date: 2019-04-08
Fix Resolution: 1.18
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: