When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2021-07-13 01:15
Updated : 2023-02-28 07:20
NVD link : CVE-2021-35515
Mitre link : CVE-2021-35515
JSON object : View
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
Products Affected
oracle
- financial_services_crime_and_compliance_management_studio
- communications_session_route_manager
- primavera_unifier
- communications_diameter_intelligence_hub
- peoplesoft_enterprise_peopletools
- commerce_guided_search
- communications_cloud_native_core_service_communication_proxy
- banking_trade_finance
- healthcare_data_repository
- financial_services_enterprise_case_management
- banking_treasury_management
- communications_cloud_native_core_unified_data_repository
- communications_messaging_server
- business_process_management_suite
- utilities_testing_accelerator
- banking_payments
- banking_party_management
- banking_enterprise_default_management
- insurance_policy_administration
- communications_cloud_native_core_automated_test_suite
- flexcube_universal_banking
- communications_billing_and_revenue_management
- banking_digital_experience
netapp
- active_iq_unified_manager
- oncommand_insight
apache
- commons_compress