Revision Date: | 2021-08-05 | Version: | 1 |
Title: | Security update for apache-commons-compress (Important) |
Description: |
This update for apache-commons-compress fixes the following issues:
- Updated to 1.21 - CVE-2021-35515: Fixed an infinite loop when reading a specially crafted 7Z archive. (bsc#1188463) - CVE-2021-35516: Fixed an excessive memory allocation when reading a specially crafted 7Z archive. (bsc#1188464) - CVE-2021-35517: Fixed an excessive memory allocation when reading a specially crafted TAR archive. (bsc#1188465) - CVE-2021-36090: Fixed an excessive memory allocation when reading a specially crafted ZIP archive. (bsc#1188466)
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1129991 1152763 1153921 1175109 1188463 1188464 1188465 1188466 CVE-2019-3695 CVE-2019-3696 CVE-2020-8231 CVE-2021-35515 CVE-2021-35516 CVE-2021-35517 CVE-2021-36090 SUSE-SU-2020:0355-1 SUSE-SU-2021:2612-1
|
Platform(s): | SUSE Linux Enterprise Desktop 15 SP3 SUSE Linux Enterprise High Performance Computing 15 SP3 SUSE Linux Enterprise Module for Development Tools 15 SP3 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 SUSE Linux Enterprise Server 15 SP3 SUSE Linux Enterprise Server for SAP Applications 15 SP3 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed AND Package Information
curl-7.60.0-3.32 is installed
OR curl-mini-7.60.0-3.32 is installed
OR libcurl-devel-32bit-7.60.0-3.32 is installed
OR libcurl-mini-devel-7.60.0-3.32 is installed
OR libcurl4-mini-7.60.0-3.32 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Development Tools 15 SP3 is installed
AND apache-commons-compress-1.21-3.3.1 is installed
|