Bug 1557542 (CVE-2018-1324)
Summary: | CVE-2018-1324 apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classes | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | aileenc, alazarot, anstephe, apevec, avibelli, bcourt, bgeorges, bkearney, bmcclain, chazlett, chrisw, cmoulliard, dffrench, drieden, drusso, eedri, etirelli, gvarsami, hhorak, ibek, java-maint, java-sig-commits, jbalunas, jcoleman, jjoyce, jmadigan, jmatthew, jolee, jorton, jpallich, jschatte, jschluet, jshepherd, jstastny, krathod, kverlaen, ldimaggi, lgriffin, lhh, lpeer, lthon, markmc, mburns, mgoldboi, michal.skrivanek, mizdebsk, mkolesni, mmccune, mszynkie, ngough, nwallace, ohadlevy, pgallagh, pwright, rbryant, rchan, rrajasek, rruss, rsynek, rwagner, rzhang, sandro, sbonazzo, sclewis, sdaley, sherold, sisharma, slinaber, SpikeFedora, tcunning, tdecacqu, tkirby, trepel, tsanders, vondruch, ykaul |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | apache-commons-compress 1.16 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2021-10-21 19:57:57 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1557543, 1558341, 1558342, 1563526, 1563527 | ||
Bug Blocks: | 1557544 |
Description
Pedro Sampaio
2018-03-16 20:25:18 UTC
Created apache-commons-compress tracking bugs for this issue: Affects: fedora-all [bug 1557543] External References: https://commons.apache.org/proper/commons-compress/security-reports.html Statement: This issue affects the versions of lucene4 as shipped with Red Hat Enterprise Satellite 6.0 and 6.1. Red Hat Satellite 6.2 and later do not include the lucene4 component and are not affected. apache-commons-compress-1.13-3.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report. apache-commons-compress-1.14-3.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report. RHMAP has a dependency on commons-compress because it's required by log4j-core. Log4j-core only uses commons-compress for compression of log files, and doesn't provide any decompression functionality. Therefore log4j-core and RHMAP are not affected by this flaw. |