[Bugs] [Bug 13214] New: ant 1.10.8 cve-s found
bugzilla
bugzilla на rosalinux.ru
Вс Апр 16 21:04:34 MSK 2023
https://bugzilla.rosalinux.ru/show_bug.cgi?id=13214
Platform: 2021.1
Bug ID: 13214
Summary: ant 1.10.8 cve-s found
Classification: ROSA-based products
Product: Certified ROSA distros
Version: Chrome
Hardware: All
OS: Linux
Status: CONFIRMED
Severity: normal
Priority: Normal
Component: System (kernel, glibc, systemd, bash, PAM...)
Assignee: bugs на lists.rosalinux.ru
Reporter: y.tumanov на rosalinux.ru
QA Contact: bugs на lists.rosalinux.ru
Target Milestone: ---
Group: ROSA-plus-NTCIT
CVE-2021-36373
When reading a specially crafted TAR archive an Apache Ant build can be
made to allocate large amounts of memory that finally leads to an out of memory
error, even for small inputs. This can be used to disrupt builds using Apache
Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
https://nvd.nist.gov/vuln/detail/CVE-2021-36373
MEDIUM
CVE-2021-36373
When reading a specially crafted TAR archive an Apache Ant build can be
made to allocate large amounts of memory that finally leads to an out of memory
error, even for small inputs. This can be used to disrupt builds using Apache
Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
https://nvd.nist.gov/vuln/detail/CVE-2021-36373
MEDIUM
CVE-2021-36374
When reading a specially crafted ZIP archive, or a derived formats, an
Apache Ant build can be made to allocate large amounts of memory that leads to
an out of memory error, even for small inputs. This can be used to disrupt
builds using Apache Ant. Commonly used derived formats from ZIP archives are
for instance JAR files and many office files. Apache Ant prior to 1.9.16 and
1.10.11 were affected.
https://nvd.nist.gov/vuln/detail/CVE-2021-36374
MEDIUM
CVE-2021-36374
When reading a specially crafted ZIP archive, or a derived formats, an
Apache Ant build can be made to allocate large amounts of memory that leads to
an out of memory error, even for small inputs. This can be used to disrupt
builds using Apache Ant. Commonly used derived formats from ZIP archives are
for instance JAR files and many office files. Apache Ant prior to 1.9.16 and
1.10.11 were affected.
https://nvd.nist.gov/vuln/detail/CVE-2021-36374
MEDIUM
--
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
----------- следущая часть -----------
Вложение в формате HTML было извлечено…
URL: <http://lists.rosalinux.ru/pipermail/bugs/attachments/20230416/22c3409e/attachment.html>
Подробная информация о списке рассылки Bugs