CVE-2024-25710

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:commons_compress:*:*:*:*:*:*:*:*

History

13 Feb 2025, 18:17

Type Values Removed Values Added
Summary (en) Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue. (en) Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue.

21 Nov 2024, 09:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 8.1
References () http://www.openwall.com/lists/oss-security/2024/02/19/1 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2024/02/19/1 - Mailing List, Third Party Advisory
References () https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf - Vendor Advisory () https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20240307-0010/ - () https://security.netapp.com/advisory/ntap-20240307-0010/ -

07 Mar 2024, 17:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240307-0010/ -

22 Feb 2024, 15:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 5.5
References () http://www.openwall.com/lists/oss-security/2024/02/19/1 - () http://www.openwall.com/lists/oss-security/2024/02/19/1 - Mailing List, Third Party Advisory
References () https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf - () https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf - Vendor Advisory
CPE cpe:2.3:a:apache:commons_compress:*:*:*:*:*:*:*:*
First Time Apache
Apache commons Compress

20 Feb 2024, 19:50

Type Values Removed Values Added
Summary
  • (es) Bucle con vulnerabilidad de condición de salida inalcanzable ("bucle infinito") en Apache Commons Compress. Este problema afecta a Apache Commons Compress: desde 1.3 hasta 1.25.0. Se recomienda a los usuarios actualizar a la versión 1.26.0, que soluciona el problema.

19 Feb 2024, 11:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/02/19/1 -

19 Feb 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-19 09:15

Updated : 2025-02-13 18:17


NVD link : CVE-2024-25710

Mitre link : CVE-2024-25710

CVE.ORG link : CVE-2024-25710


JSON object : View

Products Affected

apache

  • commons_compress
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')