imPC@ndo IT

Tracker / CVE-2021-35517

CVE-2021-35517

High 7.5

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.

Affected products and versions

apache commons_compress · 1.1 → 1.20
netapp active_iq_unified_manager
netapp oncommand_insight
oracle banking_apis
oracle banking_apis · 18.1 → 18.3
oracle banking_digital_experience
oracle banking_digital_experience · 18.1 → 18.3
oracle banking_enterprise_default_management
oracle banking_party_management
oracle banking_payments
oracle banking_trade_finance
oracle banking_treasury_management
oracle business_process_management_suite
oracle commerce_guided_search
oracle communications_billing_and_revenue_management
oracle communications_cloud_native_core_service_communication_proxy
oracle communications_cloud_native_core_unified_data_repository
oracle communications_diameter_intelligence_hub · 8.0.0 → 8.2.3
oracle communications_messaging_server
oracle communications_session_route_manager · 8.0.0 → 8.2.5
oracle financial_services_crime_and_compliance_management_studio
oracle financial_services_enterprise_case_management
oracle flexcube_universal_banking
oracle flexcube_universal_banking · 14.0.0 → 14.3.0
oracle healthcare_data_repository
oracle insurance_policy_administration
oracle peoplesoft_enterprise_peopletools
oracle primavera_unifier
oracle primavera_unifier · 17.7 → 17.12
oracle utilities_testing_accelerator
oracle webcenter_portal

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References