MGASA-2022-0009

Source
https://advisories.mageia.org/MGASA-2022-0009.html
Import Source
https://advisories.mageia.org/MGASA-2022-0009.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0009
Related
Published
2022-01-11T07:12:42Z
Modified
2022-01-11T06:35:52Z
Summary
Updated osgi-core/apache-commons-compress packages fix security vulnerability
Details

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. (CVE-2021-35515) When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package. (CVE-2021-35516) When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package. (CVE-2021-35517) When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package. (CVE-2021-36090)

References
Credits

Affected packages

Mageia:8 / osgi-core

Package

Name
osgi-core
Purl
pkg:rpm/mageia/osgi-core?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.0.0-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / apache-commons-compress

Package

Name
apache-commons-compress
Purl
pkg:rpm/mageia/apache-commons-compress?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.21-1.mga8

Ecosystem specific

{
    "section": "core"
}