#VU108024 Improper Handling of Length Parameter Inconsistency in Apache Commons Compress - CVE-2021-33517
Published: April 29, 2025
Apache Commons Compress
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists because during reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. A remote attacker can trigger the vulnerability and perform a denial of service (DoS) attack.