Nov 12, 2018 8:01 am EDT
Categorized: Low Severity
Share this post:
Apache Commons Compress is vulnerable to a denial of service, caused by the failure to return the correct EOF indication after the end of the stream has been reached by the ZipArchiveInputStream method. By reading a specially crafted ZIP archive, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop. IBM Network Performance Insight has addressed this.
Affected product(s) and affected version(s):
IBM Network Performance Insight: 1.2.1, 1.2.2, 1.2.3.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10739173
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148429