CVE-2021-35517

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
apachecommons_compress
1.1 ≤
𝑥
≤ 1.20
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netapponcommand_insight
-
oraclebanking_apis
18.1 ≤
𝑥
≤ 18.3
oraclebanking_apis
19.1
oraclebanking_apis
19.2
oraclebanking_apis
20.1
oraclebanking_apis
21.1
oraclebanking_digital_experience
18.1 ≤
𝑥
≤ 18.3
oraclebanking_digital_experience
19.1
oraclebanking_digital_experience
19.2
oraclebanking_digital_experience
20.1
oraclebanking_digital_experience
21.1
oraclebanking_enterprise_default_management
2.7.0
oraclebanking_party_management
2.7.0
oraclebanking_payments
14.5
oraclebanking_trade_finance
14.5
oraclebanking_treasury_management
14.5
oraclebusiness_process_management_suite
12.2.1.3.0
oraclebusiness_process_management_suite
12.2.1.4.0
oraclecommerce_guided_search
11.3.2
oraclecommunications_billing_and_revenue_management
12.0.0.4
oraclecommunications_cloud_native_core_service_communication_proxy
1.14.0
oraclecommunications_cloud_native_core_unified_data_repository
1.14.0
oraclecommunications_diameter_intelligence_hub
8.0.0 ≤
𝑥
≤ 8.2.3
oraclecommunications_session_route_manager
8.0.0 ≤
𝑥
≤ 8.2.5
oraclefinancial_services_crime_and_compliance_management_studio
8.0.8.2.0
oraclefinancial_services_crime_and_compliance_management_studio
8.0.8.3.0
oraclefinancial_services_enterprise_case_management
8.0.7.2.0
oraclefinancial_services_enterprise_case_management
8.0.8.1.0
oracleflexcube_universal_banking
14.0.0 ≤
𝑥
≤ 14.3.0
oracleflexcube_universal_banking
12.4
oracleflexcube_universal_banking
14.5
oraclehealthcare_data_repository
8.1.0
oracleinsurance_policy_administration
11.0.2
oracleinsurance_policy_administration
11.1.0
oracleinsurance_policy_administration
11.2.8
oracleinsurance_policy_administration
11.3.0
oracleinsurance_policy_administration
11.3.1
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oracleprimavera_unifier
17.7 ≤
𝑥
≤ 17.12
oracleprimavera_unifier
18.8
oracleprimavera_unifier
19.12
oracleprimavera_unifier
20.12
oracleutilities_testing_accelerator
6.0.0.1.1
oracleutilities_testing_accelerator
6.0.0.2.2
oracleutilities_testing_accelerator
6.0.0.3.1
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
oraclecommunications_messaging_server
8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libcommons-compress-java
bullseye
no-dsa
buster
no-dsa
stretch
no-dsa
bookworm
1.22-1
fixed
sid
1.27.1-2
fixed
trixie
1.27.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libcommons-compress-java
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
dne
References