OESA-2021-1302

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1302
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1302.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2021-1302
Upstream
Published
2021-08-06T11:03:07Z
Modified
2025-08-12T05:08:58.342336Z
Summary
apache-commons-compress security update
Details

The Apache Commons Compress library defines an API for working with ar, cpio, Unix dump, tar, zip, gzip, XZ, Pack200 and bzip2 files.

Security Fix(es):

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.(CVE-2021-35517)

When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.(CVE-2021-35516)

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.(CVE-2021-35515)

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.(CVE-2021-36090)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / apache-commons-compress

Package

Name
apache-commons-compress
Purl
pkg:rpm/openEuler/apache-commons-compress&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.21-1.oe1

Ecosystem specific

{
    "src": [
        "apache-commons-compress-1.21-1.oe1.src.rpm"
    ],
    "noarch": [
        "apache-commons-compress-1.21-1.oe1.noarch.rpm",
        "apache-commons-compress-help-1.21-1.oe1.noarch.rpm"
    ]
}

openEuler:20.03-LTS-SP2 / apache-commons-compress

Package

Name
apache-commons-compress
Purl
pkg:rpm/openEuler/apache-commons-compress&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.21-1.oe1

Ecosystem specific

{
    "src": [
        "apache-commons-compress-1.21-1.oe1.src.rpm"
    ],
    "noarch": [
        "apache-commons-compress-1.21-1.oe1.noarch.rpm",
        "apache-commons-compress-help-1.21-1.oe1.noarch.rpm"
    ]
}