CVE-2018-1324
published 2018-03-16CVE-2018-1324: A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and…
PriorityP425medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
3.68%
88.5th percentile
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_compress | 1.11 – 1.15 | — |
| apache | tika | — | — |
| apache_software_foundation | apache_commons_compress | — | — |
| debian | libcommons-compress-java | < libcommons-compress-java 1.13-2 (bookworm) | libcommons-compress-java 1.13-2 (bookworm) |
| oracle | mysql_cluster | <= 7.4.34 | — |
| oracle | mysql_cluster | 7.5.0 – 7.5.24 | — |
| oracle | mysql_cluster | 7.6.0 – 7.6.20 | — |
| oracle | mysql_cluster | 8.0.0 – 8.0.27 | — |
| oracle | weblogic_server | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_apache5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Commons Compress vulnerable to denial of service due to infinite loop
osv·2019-03-14
CVE-2018-1324 [MEDIUM] Apache Commons Compress vulnerable to denial of service due to infinite loop
Apache Commons Compress vulnerable to denial of service due to infinite loop
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
GHSA
Apache Commons Compress vulnerable to denial of service due to infinite loop
ghsa·2019-03-14
CVE-2018-1324 [MEDIUM] CWE-835 Apache Commons Compress vulnerable to denial of service due to infinite loop
Apache Commons Compress vulnerable to denial of service due to infinite loop
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
OSV
CVE-2018-1324: A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and Zi
osv·2018-03-16·CVSS 5.5
CVE-2018-1324 [MEDIUM] CVE-2018-1324: A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and Zi
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WLST (Apache Commons Compress) — CVE-2018-1324
vendor_oracle·2022-01-15·CVSS 5.5
CVE-2018-1324 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: WLST (Apache Commons Compress) — CVE-2018-1324
Oracle Oracle Fusion Middleware Risk Matrix: WLST (Apache Commons Compress) vulnerability
CVE: CVE-2018-1324
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2022 (JAN 2022)
Red Hat
apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classes
vendor_redhat·2018-03-16·CVSS 5.5
CVE-2018-1324 [MEDIUM] CWE-190 apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classes
apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classes
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
Statement: This issue affects the versions of lucene4 as shipped with Red Hat Enterprise Satellite 6.0 and 6.1. Red Hat Satellite 6.2 and later do not include the lucene4 component and are not affected.
Package: commons-compress (JBoss Developer Studio 11) - Not affected
Package: commons-compress (Red Hat BPM Suite 6) - Not affected
Package: apache-commons-compress (Red Hat Enter
Debian
CVE-2018-1324: libcommons-compress-java - A specially crafted ZIP archive can be used to cause an infinite loop inside of ...
vendor_debian·2018·CVSS 5.5
CVE-2018-1324 [MEDIUM] CVE-2018-1324: libcommons-compress-java - A specially crafted ZIP archive can be used to cause an infinite loop inside of ...
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
Scope: local
bookworm: resolved (fixed in 1.13-2)
bullseye: resolved (fixed in 1.13-2)
forky: resolved (fixed in 1.13-2)
sid: resolved (fixed in 1.13-2)
trixie: resolved (fixed in 1.13-2)
Apache
Apache tika: CVE-2018-1324
vendor_apache·CVSS 5.5
CVE-2018-1324 [MEDIUM] Apache tika: CVE-2018-1324
Apache tika: CVE-2018-1324
and COMPRESS-432 Commons Compress - Infinite loop in ZipFile Luís Filipe Nassif and Anton Abashkin ?-1.17
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1324 apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classes [fedora-all]
bugzilla·2018-03-16·CVSS 5.5
CVE-2018-1324 [MEDIUM] CVE-2018-1324 apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classes [fedora-all]
CVE-2018-1324 apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classes [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
Bugzilla
CVE-2018-1324 apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classes
bugzilla·2018-03-16·CVSS 5.5
CVE-2018-1324 [MEDIUM] CVE-2018-1324 apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classes
CVE-2018-1324 apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classes
A flaw was found in Apache Commons Compress versions 1.11 to 1.15. A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
Upstream patch:
https://git-wip-us.apache.org/repos/asf?p=commons-compress.git;a=blobdiff;f=src/main/java/org/apache/commons/compress/archivers/zip/X0017_StrongEncryptionHeader.java;h=acc3b22346b49845e85b5ef27a5814b69e834139;hp=0feb9c98cc622cde1defa3bbd268ef82b4ae5c18;hb=2a2f1dc48e22a34ddb72321a4db211d
arXiv
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
arxiv_fulltext·2026-03
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
## Abstract
Open-source software supply chain security relies heavily on assessing affected versions of library vulnerabilities. While prior studies have leveraged exploits for verifying vulnerability affected versions, they point out a key limitation that exploits are version-specific and cannot be directly applied across library versions. Despite being widely acknowledged, this limitation has not been systematically validated at scale, leaving the actual applicability of exploits across versions unexplored. To fill this gap, we conduct the first large-scale empirical study on exploit applicability across library versions. We construct a comprehensive dataset consisting of 259 exploits spanning 128 Java libraries and 28,150 historical versions, covering 61 CWEs that account for 76.33% of
http://www.securityfocus.com/bid/103490http://www.securitytracker.com/id/1040549https://lists.apache.org/thread.html/1c7b6df6d1c5c8583518a0afa017782924918e4d6acfaf23ed5b2089%40%3Cdev.commons.apache.org%3Ehttps://lists.apache.org/thread.html/b8ef29df0f1d55aa741170748352ae8e425c7b1d286b2f257711a2dd%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r5532dc8d5456b5151e8c286801e2e5769f5c04118b29c3b5d13ea387%40%3Cissues.beam.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujan2022.htmlhttp://www.securityfocus.com/bid/103490http://www.securitytracker.com/id/1040549https://lists.apache.org/thread.html/1c7b6df6d1c5c8583518a0afa017782924918e4d6acfaf23ed5b2089%40%3Cdev.commons.apache.org%3Ehttps://lists.apache.org/thread.html/b8ef29df0f1d55aa741170748352ae8e425c7b1d286b2f257711a2dd%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r5532dc8d5456b5151e8c286801e2e5769f5c04118b29c3b5d13ea387%40%3Cissues.beam.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujan2022.html
2018-03-16
Published