CVE-2021-36090: Apache Commons Compress 1.0 to 1.20 denial of service vulnerability
A flaw was found in apache-commons-compress. When reading a specially crafted ZIP archive, Compress can allocate large amounts of memory that leads to an out-of-memory error for small inputs. This flaw allows the mounting of a denial of service attack against services that use Compress' zip package. The highest threat from this vulnerability is to system availability.
Other sources
Apache Commons Compress is vulnerable to a denial of service, caused by an out-of-memory error when large amounts of memory are allocated. By reading a specially-crafted ZIP archive, a remote attacker could exploit this vulnerability to cause a denial of service condition against services that use Compress' zip package.
— IBM
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-36090?
CVE-2021-36090 is classified as a medium severity vulnerability due to its potential for causing denial of service through excessive memory allocation.
How do I fix CVE-2021-36090?
To fix CVE-2021-36090, update the affected software to version 1.21 or higher for apache-commons-compress.
What types of software are affected by CVE-2021-36090?
CVE-2021-36090 affects various versions of apache-commons-compress, as well as several Oracle products and IBM Cloud Pak System.
What is the impact of exploiting CVE-2021-36090?
Exploiting CVE-2021-36090 can result in a denial of service condition by causing an out-of-memory error on the affected systems.
Is CVE-2021-36090 publicly disclosed?
Yes, CVE-2021-36090 has been publicly disclosed and documented in various security reports.