Insecure functionality In org.apache.commons:commons-compress
Description
Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress. This issue affects Apache Commons Compress: from 1.3 through 1.25.0.
Users are recommended to upgrade to version 1.26.0 which fixes the issue.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 1.26.0 | ||
debian 12 | - | ||
debian 13 | 1.27.1-1 | ||
debian 14 | 1.27.1-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4.