CVE-2021-35516: Apache Commons Compress 1.6 to 1.20 denial of service vulnerability
A flaw was found in apache-commons-compress. When reading a specially crafted 7Z archive, Compress can allocate large amounts of memory that leads to an out-of-memory error for very small inputs. This flaw allows the mounting of a denial of service attack against services that use Compress' SevenZ package. The highest threat from this vulnerability is to system availability.
Other sources
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw in apache-commons-compress?
The vulnerability ID of this flaw in apache-commons-compress is CVE-2021-35516.
What is the severity of CVE-2021-35516?
The severity of CVE-2021-35516 is high with a severity value of 7.5.
Which software is affected by CVE-2021-35516?
The software affected by CVE-2021-35516 is apache-commons-compress version up to 1.21.
How can this vulnerability be exploited?
This vulnerability can be exploited by reading a specially crafted 7Z archive that causes Compress to allocate large amounts of memory.
Are there any remediation steps available for CVE-2021-35516?
Yes, the remedy for CVE-2021-35516 is to update apache-commons-compress to version 1.21 or higher.