Improper input validation in Apache Commons Compress - CVE-2018-11771
Published: August 16, 2018 / Updated: August 17, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to an error when processing malicious input. A remote attacker can trick the victim into processing a specially crafted ZIP archive with 'java.io.InputStreamReader', trigger an error in detecting the end of the file and cause the service to crash.
Affected software
IBM Observability with Instana
IBM PureData System for Operational Analytics
Netcool Operations Insight
IBM Cloud Application Performance Management (APM)
Fuse
Fedora
apache-commons-compress
Storage Virtualize
How to mitigate CVE-2018-11771
Fuse - update to 7.6.0
Netcool Operations Insight - update to 1.6.10
apache-commons-compress - addressed in versions 1.16.1-2.fc28, 1.17-3.fc29
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
External References
Related Security Bulletins
- Denial of service in Apache Commons Compress
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM Storage Virtualize
- Fedora 29 update for apache-commons-compress
- Fedora 28 update for apache-commons-compress