Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31465
HistoryAug 03, 2021 - 5:06 a.m.

Denial Of Service (DoS)

2021-08-0305:06:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.012 Low

EPSS

Percentile

85.1%

commons-compress is vulnerable to denial of service. When reading a specially crafted ZIP archive, large amounts of memory can be made to be alloocated, which would lead to an out of memory error for small inputs. This could be used to mount a denial of service attack against services that use Compress’ zip package.

References