Oval Definition:oval:org.opensuse.security:def:74656
Revision Date:2021-08-05Version:1
Title:Security update for apache-commons-compress (Important)
Description:

This update for apache-commons-compress fixes the following issues:

- Updated to 1.21 - CVE-2021-35515: Fixed an infinite loop when reading a specially crafted 7Z archive. (bsc#1188463) - CVE-2021-35516: Fixed an excessive memory allocation when reading a specially crafted 7Z archive. (bsc#1188464) - CVE-2021-35517: Fixed an excessive memory allocation when reading a specially crafted TAR archive. (bsc#1188465) - CVE-2021-36090: Fixed an excessive memory allocation when reading a specially crafted ZIP archive. (bsc#1188466)
Family:unixClass:patch
Status:Reference(s):1157594
1167208
1167623
1177967
1188463
1188464
1188465
1188466
CVE-2019-12921
CVE-2020-10938
CVE-2020-15917
CVE-2021-35515
CVE-2021-35516
CVE-2021-35517
CVE-2021-36090
openSUSE-SU-2020:0416-1
openSUSE-SU-2020:1822-1
SUSE-SU-2021:2612-1
Platform(s):openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Development Tools 15 SP2
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Storage 7
SUSE Manager Proxy 4.1
SUSE Manager Server 4.1
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • claws-mail-3.17.8-lp152.3.6 is installed
  • OR claws-mail-devel-3.17.8-lp152.3.6 is installed
  • OR claws-mail-lang-3.17.8-lp152.3.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Development Tools 15 SP2 is installed
  • AND apache-commons-compress-1.21-3.3.1 is installed
  • BACK