<html>
<head>
<base href="https://bugzilla.rosalinux.ru/">
</head>
<body><table border="1" cellspacing="0" cellpadding="8">
<tr>
<th>Platform</th>
<td>2021.1
</td>
</tr>
<tr>
<th>Bug ID</th>
<td><a class="bz_bug_link
bz_status_CONFIRMED "
title="CONFIRMED - ant 1.10.8 cve-s found"
href="https://bugzilla.rosalinux.ru/show_bug.cgi?id=13214">13214</a>
</td>
</tr>
<tr>
<th>Summary</th>
<td>ant 1.10.8 cve-s found
</td>
</tr>
<tr>
<th>Classification</th>
<td>ROSA-based products
</td>
</tr>
<tr>
<th>Product</th>
<td>Certified ROSA distros
</td>
</tr>
<tr>
<th>Version</th>
<td>Chrome
</td>
</tr>
<tr>
<th>Hardware</th>
<td>All
</td>
</tr>
<tr>
<th>OS</th>
<td>Linux
</td>
</tr>
<tr>
<th>Status</th>
<td>CONFIRMED
</td>
</tr>
<tr>
<th>Severity</th>
<td>normal
</td>
</tr>
<tr>
<th>Priority</th>
<td>Normal
</td>
</tr>
<tr>
<th>Component</th>
<td>System (kernel, glibc, systemd, bash, PAM...)
</td>
</tr>
<tr>
<th>Assignee</th>
<td>bugs@lists.rosalinux.ru
</td>
</tr>
<tr>
<th>Reporter</th>
<td>y.tumanov@rosalinux.ru
</td>
</tr>
<tr>
<th>QA Contact</th>
<td>bugs@lists.rosalinux.ru
</td>
</tr>
<tr>
<th>Target Milestone</th>
<td>---
</td>
</tr>
<tr>
<th>Group</th>
<td>ROSA-plus-NTCIT
</td>
</tr></table>
<p>
<div>
<pre>CVE-2021-36373
When reading a specially crafted TAR archive an Apache Ant build can be
made to allocate large amounts of memory that finally leads to an out of memory
error, even for small inputs. This can be used to disrupt builds using Apache
Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
<a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36373">https://nvd.nist.gov/vuln/detail/CVE-2021-36373</a>
MEDIUM
CVE-2021-36373
When reading a specially crafted TAR archive an Apache Ant build can be
made to allocate large amounts of memory that finally leads to an out of memory
error, even for small inputs. This can be used to disrupt builds using Apache
Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
<a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36373">https://nvd.nist.gov/vuln/detail/CVE-2021-36373</a>
MEDIUM
CVE-2021-36374
When reading a specially crafted ZIP archive, or a derived formats, an
Apache Ant build can be made to allocate large amounts of memory that leads to
an out of memory error, even for small inputs. This can be used to disrupt
builds using Apache Ant. Commonly used derived formats from ZIP archives are
for instance JAR files and many office files. Apache Ant prior to 1.9.16 and
1.10.11 were affected.
<a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36374">https://nvd.nist.gov/vuln/detail/CVE-2021-36374</a>
MEDIUM
CVE-2021-36374
When reading a specially crafted ZIP archive, or a derived formats, an
Apache Ant build can be made to allocate large amounts of memory that leads to
an out of memory error, even for small inputs. This can be used to disrupt
builds using Apache Ant. Commonly used derived formats from ZIP archives are
for instance JAR files and many office files. Apache Ant prior to 1.9.16 and
1.10.11 were affected.
<a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36374">https://nvd.nist.gov/vuln/detail/CVE-2021-36374</a>
MEDIUM</pre>
</div>
</p>
<hr>
<span>You are receiving this mail because:</span>
<ul>
<li>You are the QA Contact for the bug.</li>
<li>You are the assignee for the bug.</li>
</ul>
</body>
</html>