When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2021-07-13 08:15
Updated : 2022-07-25 18:15
NVD link : CVE-2021-35515
Mitre link : CVE-2021-35515
JSON object : View
Products Affected
oracle
- banking_digital_experience
- banking_party_management
- insurance_policy_administration
- flexcube_universal_banking
- utilities_testing_accelerator
- financial_services_enterprise_case_management
- commerce_guided_search
- communications_diameter_intelligence_hub
- communications_session_route_manager
- primavera_unifier
- peoplesoft_enterprise_peopletools
- business_process_management_suite
- communications_cloud_native_core_unified_data_repository
- banking_enterprise_default_management
- communications_messaging_server
- banking_trade_finance
- healthcare_data_repository
- communications_billing_and_revenue_management
- banking_treasury_management
- communications_cloud_native_core_service_communication_proxy
- banking_payments
- communications_cloud_native_core_automated_test_suite
netapp
- active_iq_unified_manager
- oncommand_insight
apache
- commons_compress
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
