Related Vulnerabilities: CVE-2021-36374  

When reading a specially crafted ZIP archive, or a derived format, Apache Ant before version 1.10.11 can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant.

Severity Low

Remote No

Type Denial of service

Description

When reading a specially crafted ZIP archive, or a derived format, Apache Ant before version 1.10.11 can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant.

AVG-2151 ant 1.10.10-1 Low Vulnerable

https://www.openwall.com/lists/oss-security/2021/07/13/6
https://github.com/apache/ant/commit/6594a2d66f7f060dafcbbf094dd60676db19a842