CVE-2021-36090

EUVD-2021-1798
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
apachecommons_compress
1.0 ≤
𝑥
< 1.21
oraclebanking_apis
18.1 ≤
𝑥
≤ 18.3
oraclebanking_apis
19.1
oraclebanking_apis
19.2
oraclebanking_apis
20.1
oraclebanking_apis
21.1
oraclebanking_digital_experience
18.1 ≤
𝑥
≤ 18.3
oraclebanking_digital_experience
19.1
oraclebanking_digital_experience
19.2
oraclebanking_digital_experience
20.1
oraclebanking_digital_experience
21.1
oraclebanking_enterprise_default_management
2.7.0
oraclebanking_party_management
2.7.0
oraclebanking_payments
14.5
oraclebanking_platform
2.6.2
oraclebanking_platform
2.7.1
oraclebanking_platform
2.9.0
oraclebanking_platform
2.12.0
oraclebanking_trade_finance
14.5
oraclebanking_treasury_management
14.5
oraclebusiness_process_management_suite
12.2.1.3.0
oraclebusiness_process_management_suite
12.2.1.4.0
oraclecommerce_guided_search
11.3.2
oraclecommunications_billing_and_revenue_management
12.0.0.4
oraclecommunications_cloud_native_core_automated_test_suite
1.8.0
oraclecommunications_cloud_native_core_service_communication_proxy
1.14.0
oraclecommunications_cloud_native_core_unified_data_repository
1.14.0
oraclecommunications_diameter_intelligence_hub
8.0.0 ≤
𝑥
≤ 8.2.3
oraclecommunications_diameter_intelligence_hub
8.2.3
oraclecommunications_element_manager
8.2.0 ≤
𝑥
≤ 8.2.4.0
oraclecommunications_session_report_manager
8.2.0 ≤
𝑥
≤ 8.2.5.0
oraclecommunications_session_route_manager
8.0.0 ≤
𝑥
≤ 8.2.5.0
oraclecommunications_unified_inventory_management
7.4.0
oraclecommunications_unified_inventory_management
7.4.1
oraclecommunications_unified_inventory_management
7.4.2
oraclecommunications_unified_inventory_management
7.5.0
oraclefinancial_services_analytical_applications_infrastructure
8.0.6 ≤
𝑥
≤ 8.1.1
oraclefinancial_services_crime_and_compliance_management_studio
8.0.8.2.0
oraclefinancial_services_crime_and_compliance_management_studio
8.0.8.3.0
oraclefinancial_services_enterprise_case_management
*
oraclefinancial_services_enterprise_case_management
8.0.7.2.0
oraclefinancial_services_enterprise_case_management
8.0.8.1.0
oracleflexcube_universal_banking
14.0.0 ≤
𝑥
≤ 14.3.0
oracleflexcube_universal_banking
12.4
oracleflexcube_universal_banking
14.5
oraclehealthcare_data_repository
8.1.0
oracleinsurance_policy_administration
11.0.2
oracleinsurance_policy_administration
11.1.0
oracleinsurance_policy_administration
11.2.8
oracleinsurance_policy_administration
11.3.0
oracleinsurance_policy_administration
11.3.1
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.11
oracleprimavera_gateway
18.8.0 ≤
𝑥
≤ 18.8.12
oracleprimavera_gateway
19.12.0 ≤
𝑥
≤ 19.12.11
oracleprimavera_gateway
20.12.0 ≤
𝑥
≤ 20.12.7
oracleprimavera_unifier
17.7 ≤
𝑥
≤ 17.12
oracleprimavera_unifier
18.8
oracleprimavera_unifier
19.12
oracleprimavera_unifier
20.12
oracleutilities_testing_accelerator
6.0.0.1.1
oracleutilities_testing_accelerator
6.0.0.2.2
oracleutilities_testing_accelerator
6.0.0.3.1
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
oraclecommunications_messaging_server
8.1
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netapponcommand_insight
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libcommons-compress-java
bookworm
1.22-1
fixed
bullseye
no-dsa
buster
no-dsa
sid
1.27.1-2
fixed
stretch
no-dsa
trixie
1.27.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libcommons-compress-java
bionic
needs-triage
focal
needs-triage
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
dne
xenial
needs-triage
References