Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-62077
HistoryJul 19, 2021 - 12:00 a.m.

Apache Commons Compress Resource Management Error Vulnerability (CNVD-2022-62077)

2021-07-1900:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.025 Low

EPSS

Percentile

90.2%

A resource management error vulnerability exists in Apache Commons Compress, a library for processing compressed files from the Apache Foundation, which stems from the fact that when reading a specially crafted 7Z archive, Compress can allocate a large amount of memory, resulting in an out-of-memory error for very out-of-memory error for very small inputs. No details of the vulnerability are currently available.