CVE-2021-36373

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-36373
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-36373.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-36373
Aliases
Downstream
Related
Published
2021-07-14T07:15:08Z
Modified
2025-10-15T04:33:44Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

References

Affected packages

Git / github.com/apache/ant

Affected ranges

Type
GIT
Repo
https://github.com/apache/ant
Events