https://seclists.org/oss-sec/2024/q1/141: CVE-2024-25710: Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
Published Feb 19, 2024
·Updated
Affected Software
1 affected component
Apache Commons Compress>=1.3<1.25.0
Frequently Asked Questions
1
What is the severity of CVE-2024-25710?
The severity of CVE-2024-25710 is classified as important.
2
Which versions are affected by CVE-2024-25710?
CVE-2024-25710 affects Apache Commons Compress from versions 1.3 through 1.25.0.
3
How do I fix CVE-2024-25710?
To fix CVE-2024-25710, users should upgrade to a version of Apache Commons Compress that is newer than 1.25.0.
4
What type of vulnerability is CVE-2024-25710?
CVE-2024-25710 is a Denial of Service vulnerability caused by an infinite loop in processing a corrupted DUMP file.
5
Is there a workaround for CVE-2024-25710?
There is no official workaround for CVE-2024-25710, and upgrading to a patched version is the recommended approach.