Improper Handling of Length Parameter Inconsistency in Apache Commons Compress - CVE-2021-33517
Published: April 29, 2025
Apache Commons Compress
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists because during reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. A remote attacker can trigger the vulnerability and perform a denial of service (DoS) attack.