/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2018-1324

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2018-1324

CGA ID

CGA-7whg-52mh-4qp2

Severity

Unknown

Description

A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs