/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2018-1324

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2018-1324

Severity

5.5

Medium

CVSS V3

Description

A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing