NewsSecurity Vulnerabilities

Apache Commons Compress ZipArchiveInputStream Denial of Service Vulnerability [CVE-2018-11771]

CVE number – CVE-2018-11771

A vulnerability in Apache Commons Compress could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on a targeted system.

The vulnerability is due to incorrect end-of-file indication by the read method of the ZipArchiveInputStream class of the affected software, which could cause an infinite stream when combined with the java.io.InputStreamReader class. An attacker could exploit this vulnerability by persuading a user on the targeted system to open a malicious .zip archive file with an application that uses the affected software. A successful exploit could cause an infinite stream, which could result in a DoS condition on the targeted system.

The Apache Software Foundation has confirmed the vulnerability and released software updates.

Analysis
  • To exploit this vulnerability, the attacker must have local access to the targeted system or may use misleading language or instructions to persuade a targeted user on the local system to open a malicious .zip archive file.
Safeguards
  • Administrators are advised to apply the appropriate updates.

    Administrators are advised to allow only trusted users to access local systems.

    Administrators are advised to allow only trusted users to have network access.

    Users are advised not to open email messages from suspicious or unrecognized sources. If users cannot verify that links or attachments included in email messages are safe, they are advised not to open them.

    Administrators are advised to monitor affected systems.

Vendor Announcements
  • The Apache Software Foundation has released a security advisory at the following link: CVE-2018-11771

Fixed Software
  • The Apache Software Foundation has released software updates at the following link: Commons Compress 1.18



Duncan

Duncan is a technology professional with over 20 years experience of working in various IT roles. He has a interest in cyber security, and has a wide range of other skills in radio, electronics and telecommunications.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.