CVE-2018-1324

Related Vulnerabilities: CVE-2018-1324  

A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.

The MITRE CVE dictionary describes this issue as:

A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.

Find out more about CVE-2018-1324 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue affects the versions of lucene4 as shipped with Red Hat Enterprise Satellite 6.0 and 6.1. Red Hat Satellite 6.2 and later do not include the lucene4 component and are not affected.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Virtualization 4 apache-commons-compress Not affected
Red Hat Software Collections for Red Hat Enterprise Linux rh-java-common-apache-commons-compress Not affected
Red Hat Software Collections for Red Hat Enterprise Linux rh-maven35-apache-commons-compress Affected
Red Hat Satellite 6 commons-compress Not affected
Red Hat OpenStack Platform 9.0 opendaylight Affected
Red Hat OpenStack Platform 8.0 (Liberty) opendaylight Affected
Red Hat OpenShift Application Runtimes 1.0 vertx Not affected
Red Hat Mobile Application Platform On-Premise 4 commons-compress Not affected
Red Hat JBoss Fuse Service Works 6 commons-compress Not affected
Red Hat JBoss Fuse 6 commons-compress Not affected
Red Hat JBoss Data Virtualization 6 commons-compress Will not fix
Red Hat JBoss BRMS 6 commons-compress Not affected
Red Hat JBoss BRMS 5 commons-compress Not affected
Red Hat JBoss BPMS 6 commons-compress Not affected
Red Hat Gluster Storage 3 commons-compress Not affected
Red Hat Enterprise Linux 7 apache-commons-compress Not affected

External References