Uploaded image for project: 'Apache Drill'
  1. Apache Drill
  2. DRILL-7981

Bump commons-compress from 1.20 to 1.21 for CVE-2021-36090

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 1.20.0
    • None
    • None

    Description

      When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

      Attachments

        Activity

          People

            luoc Cong Luo
            luoc Cong Luo
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: