cbcvebase.
CVE-2021-36374
published 2021-07-14

CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Affected

90 ranges· showing 25
VendorProductVersion rangeFixed in
apacheant>= 0 < 1.10.11-11.10.11-1
apacheant>= 0 < 1.10.11-11.10.11-1
apacheant>= 0 < 1.10.11-11.10.11-1
apacheant>= 1.10.0 < 1.10.111.10.11
apacheant>= 1.9.0 < 1.9.161.9.16
apache_software_foundationapache_ant>= 1.4 < Apache Ant*Apache Ant*
apache_software_foundationapache_antApache Ant 1.10.x – 1.10.10
apache_software_foundationapache_antApache Ant 1.9.x – 1.9.15
debianant< ant 1.10.11-1 (bookworm)ant 1.10.11-1 (bookworm)
msrcazl3_javapackages-bootstrap_1.14.0-2_on_azure_linux_3.0
msrcazl3_javapackages-bootstrap_1.5.0-4_on_azure_linux_3.0
msrccbl2_javapackages-bootstrap_1.5.0-6_on_cbl_mariner_2.0
msrccm1_ant_1.10.11-1_on_cbl_mariner_1.0
oracleagile_engineering_data_management
oracleagile_plm
oraclebanking_trade_finance
oraclebanking_treasury_management
oraclecommunications_cloud_native_core_automated_test_suite
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_diameter_intelligence_hub8.0.0 – 8.1.0
oraclecommunications_diameter_intelligence_hub8.2.0 – 8.2.3
oraclecommunications_order_and_service_management
oraclecommunications_order_and_service_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM