CVE-2021-36374
Summary
| CVE | CVE-2021-36374 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-14 07:15:00 UTC |
| Updated | 2023-11-07 03:36:00 UTC |
| Description | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache Ant - Apache Ant Security Reports | MISC | ant.apache.org | |
| [groovy-notifications] 20210715 [jira] [Resolved] (GROOVY-10169) Bump Ant version to 1.10.11 (incorporates CVE-2021-36373 and CVE-2021-36374) | lists.apache.org | ||
| lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314d50bc1ed... | MISC | lists.apache.org | |
| Oracle Critical Patch Update Advisory - April 2022 | MISC | www.oracle.com | |
| July 2021 Apache Ant Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Oracle Critical Patch Update Advisory - October 2021 | MISC | www.oracle.com | |
| [groovy-commits] 20210715 [groovy] 02/07: GROOVY-10169: Bump Ant version to 1.10.11 (incorporates CVE-2021-36373 and CVE-2021-36374) | lists.apache.org | ||
| Oracle Critical Patch Update Advisory - January 2022 | MISC | www.oracle.com | |
| [groovy-commits] 20210714 [groovy] 08/09: GROOVY-10169: Bump Ant version to 1.10.11 (incorporates CVE-2021-36373 and CVE-2021-36374) | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| [myfaces-dev] 20210830 [GitHub] [myfaces-tobago] lofwyr14 opened a new pull request #1215: build: CVE fix | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Oracle Critical Patch Update Advisory - July 2022 | N/A | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This issue is similar to https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36090 present in Apache Commons Compress which has been detected by OSS Fuzz.
Legacy QID Mappings
- 150735 Oracle WebLogic Server Multiple Vulnerabilities (CPU - OCT2023)
- 182126 Debian Security Update for ant (CVE-2021-36374)
- 296065 Oracle Solaris 11.4 Support Repository Update (SRU) 39.107.1 Missing (CPUOCT2021)
- 354116 Amazon Linux Security Advisory for ant : ALAS2-2022-1880
- 376123 IBM Installation Manager Multiple Vulnerabilities
- 501805 Alpine Linux Security Update for apache-ant
- 504580 Alpine Linux Security Update for apache-ant
- 670695 EulerOS Security Update for ant (EulerOS-SA-2021-2453)
- 670958 EulerOS Security Update for ant (EulerOS-SA-2021-2651)
- 671660 EulerOS Security Update for ant (EulerOS-SA-2022-1703)
- 752076 SUSE Enterprise Linux Security Update for ant (SUSE-SU-2022:1417-1)
- 753206 SUSE Enterprise Linux Security Update for ant (SUSE-SU-2022:1418-1)
- 87548 Oracle WebLogic Server Multiple Vulnerabilities (CPUOCT2023)
- 900240 CBL-Mariner Linux Security Update for ant 1.10.9
- 903404 Common Base Linux Mariner (CBL-Mariner) Security Update for ant (4438)
- 980362 Java (maven) Security Update for org.apache.ant:ant (GHSA-5v34-g2px-j4fw)