#VU14441 Improper input validation in Apache Commons Compress - CVE-2018-11771
Published: August 16, 2018 / Updated: August 17, 2018
Apache Commons Compress
Apache Foundation
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to an error when processing malicious input. A remote attacker can trick the victim into processing a specially crafted ZIP archive with 'java.io.InputStreamReader', trigger an error in detecting the end of the file and cause the service to crash.