https://seclists.org/oss-sec/2024/q1/142: CVE-2024-26308: Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file
Published Feb 19, 2024
·Updated
Affected Software
1 affected component
Apache Commons Compress<1.26.0
Frequently Asked Questions
1
What is the severity of CVE-2024-26308?
The severity of CVE-2024-26308 is rated as moderate.
2
What versions of Apache Commons Compress are affected by CVE-2024-26308?
Apache Commons Compress versions before 1.26.0, specifically 1.21 and earlier, are affected by CVE-2024-26308.
3
How do I fix CVE-2024-26308?
To fix CVE-2024-26308, you should upgrade Apache Commons Compress to version 1.26 or later.
4
What type of vulnerability is CVE-2024-26308?
CVE-2024-26308 is an Allocation of Resources Without Limits or Throttling vulnerability.
5
What impact does CVE-2024-26308 have on users of Apache Commons Compress?
CVE-2024-26308 may lead to an OutOfMemoryError when unpacking broken Pack200 files, affecting application stability.