cbcvebase.
CVE-2018-1324
published 2018-03-16

CVE-2018-1324: A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and…

PriorityP425medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
3.68%
88.5th percentile
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.

Affected

9 ranges
VendorProductVersion rangeFixed in
apachecommons_compress1.11 – 1.15
apachetika
apache_software_foundationapache_commons_compress
debianlibcommons-compress-java< libcommons-compress-java 1.13-2 (bookworm)libcommons-compress-java 1.13-2 (bookworm)
oraclemysql_cluster<= 7.4.34
oraclemysql_cluster7.5.0 – 7.5.24
oraclemysql_cluster7.6.0 – 7.6.20
oraclemysql_cluster8.0.0 – 8.0.27
oracleweblogic_server

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_apache5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.