cbcvebase.
CVE-2021-36373
published 2021-07-14

CVE-2021-36373: When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error…

PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
2.51%
83.0th percentile
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Affected

83 ranges· showing 25
VendorProductVersion rangeFixed in
apacheant>= 0 < 1.10.11-11.10.11-1
apacheant>= 0 < 1.10.11-11.10.11-1
apacheant>= 0 < 1.10.11-11.10.11-1
apacheant>= 1.10.0 < 1.10.111.10.11
apacheant>= 1.9.0 < 1.9.161.9.16
apache_software_foundationapache_antApache Ant 1.10.x – 1.10.10
apache_software_foundationapache_antApache Ant 1.9.x – 1.9.15
debianant< ant 1.10.11-1 (bookworm)ant 1.10.11-1 (bookworm)
msrcazl3_javapackages-bootstrap_1.14.0-2_on_azure_linux_3.0
msrcazl3_javapackages-bootstrap_1.5.0-4_on_azure_linux_3.0
msrccbl2_javapackages-bootstrap_1.5.0-6_on_cbl_mariner_2.0
msrccm1_ant_1.10.11-1_on_cbl_mariner_1.0
oracleagile_plm
oraclebanking_trade_finance
oraclebanking_treasury_management
oraclecommunications_cloud_native_core_automated_test_suite
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_order_and_service_management
oraclecommunications_order_and_service_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oracleenterprise_repository

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.