CVE-2018-11771 PUBLISHED

When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service attack against services that use Compress' zip package.

EPSS 1.08% · 77.8th percentile

Risk Scores

EPSS Score
1.08%
77.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlibcommons-compress-java1.18-1~18.04, 0, 1.13-1
Ubuntu:16.04:LTSlibcommons-compress-java0, 1.9-1, 1.10-1

Timeline

References

Open in Interactive Console →