Infinite Loop Vulnerability in Apache Commons Compress
CVE-2024-25710

5.5MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
19 February 2024

Badges

📰 News Worthy

Summary

An infinite loop vulnerability exists in Apache Commons Compress, affecting versions from 1.3 through 1.25.0. This flaw could lead to applications becoming unresponsive, as the control flow may enter a loop with no reachable exit condition. Users are strongly advised to upgrade to version 1.26.0 or later, which addresses this issue and enhances overall security.

Affected Version(s)

Apache Commons Compress 1.3 <= 1.25.0

News Articles

CVE-2024-25710 : APACHE COMMONS COMPRESS UP TO 1.25.0 INFINITE LOOP - Cloud WAF

CVE-2024-25710 : Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by prophaze.com

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yakov Shafranovich, Amazon Web Services
.