Improper input validation in Apache Commons Compress - CVE-2018-11771

 

Improper input validation in Apache Commons Compress - CVE-2018-11771

Published: August 16, 2018 / Updated: August 17, 2018


Vulnerability identifier: #VU14441
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11771
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to an error when processing malicious input. A remote attacker can trick the victim into processing a specially crafted ZIP archive with 'java.io.InputStreamReader', trigger an error in detecting the end of the file and cause the service to crash.


Affected software

Apache Commons Compress
IBM Observability with Instana
IBM PureData System for Operational Analytics
Netcool Operations Insight
IBM Cloud Application Performance Management (APM)
Fuse
Fedora
apache-commons-compress
Storage Virtualize

How to mitigate CVE-2018-11771

Update to version 1.18.

Apache Commons Compress - update to 1.18
Fuse - update to 7.6.0
Netcool Operations Insight - update to 1.6.10
apache-commons-compress - addressed in versions 1.16.1-2.fc28, 1.17-3.fc29
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0

External References

Related Security Bulletins