[Bugs] [Bug 13214] New: ant 1.10.8 cve-s found

bugzilla bugzilla на rosalinux.ru
Вс Апр 16 21:04:34 MSK 2023


https://bugzilla.rosalinux.ru/show_bug.cgi?id=13214

          Platform: 2021.1
            Bug ID: 13214
           Summary: ant 1.10.8 cve-s found
    Classification: ROSA-based products
           Product: Certified ROSA distros
           Version: Chrome
          Hardware: All
                OS: Linux
            Status: CONFIRMED
          Severity: normal
          Priority: Normal
         Component: System (kernel, glibc, systemd, bash, PAM...)
          Assignee: bugs на lists.rosalinux.ru
          Reporter: y.tumanov на rosalinux.ru
        QA Contact: bugs на lists.rosalinux.ru
  Target Milestone: ---
             Group: ROSA-plus-NTCIT

CVE-2021-36373
        When reading a specially crafted TAR archive an Apache Ant build can be
made to allocate large amounts of memory that finally leads to an out of memory
error, even for small inputs. This can be used to disrupt builds using Apache
Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
        https://nvd.nist.gov/vuln/detail/CVE-2021-36373
        MEDIUM

CVE-2021-36373
        When reading a specially crafted TAR archive an Apache Ant build can be
made to allocate large amounts of memory that finally leads to an out of memory
error, even for small inputs. This can be used to disrupt builds using Apache
Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
        https://nvd.nist.gov/vuln/detail/CVE-2021-36373
        MEDIUM

CVE-2021-36374
        When reading a specially crafted ZIP archive, or a derived formats, an
Apache Ant build can be made to allocate large amounts of memory that leads to
an out of memory error, even for small inputs. This can be used to disrupt
builds using Apache Ant. Commonly used derived formats from ZIP archives are
for instance JAR files and many office files. Apache Ant prior to 1.9.16 and
1.10.11 were affected.
        https://nvd.nist.gov/vuln/detail/CVE-2021-36374
        MEDIUM

CVE-2021-36374
        When reading a specially crafted ZIP archive, or a derived formats, an
Apache Ant build can be made to allocate large amounts of memory that leads to
an out of memory error, even for small inputs. This can be used to disrupt
builds using Apache Ant. Commonly used derived formats from ZIP archives are
for instance JAR files and many office files. Apache Ant prior to 1.9.16 and
1.10.11 were affected.
        https://nvd.nist.gov/vuln/detail/CVE-2021-36374
        MEDIUM

-- 
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
----------- следущая часть -----------
Вложение в формате HTML было извлечено…
URL: <http://lists.rosalinux.ru/pipermail/bugs/attachments/20230416/22c3409e/attachment.html>


Подробная информация о списке рассылки Bugs